Cyber Resilience
← All news
Corroborated3

Inc Ransomware Exploits SonicWall SMA Zero-Days

Corroborated: Inc ransomware chained two SonicWall SMA zero-days (CVE-2026-15409/15410) for root on VPN appliances, active since June 22—weeks before disclosure. If you run SMA 1000, patch and hunt now; cloud-VPN lean-IT shops can ignore this, edge-SMA estates cannot.
Sources (2)
What this means for you — CISO:Patch SonicWall SMA 1000 now for CVE-2026-15409 and CVE-2026-15410; Volexity confirms exploitation began June 22, weeks before disclosure — assume compromise if you run these appliances unpatched, hunt for custom malware, not just apply the patch.
What this means for you — Lean IT orgs:If you use a SonicWall SMA appliance for remote access VPN, patch it today and check logs back to June 22 for signs of intrusion — this isn't a wait-for-your-normal-cycle fix.
What this means for you — MSP:Inventory every client running SonicWall SMA 1000 gateways, patch immediately, and treat any unpatched instance since June 22 as a potential root-level compromise requiring investigation, not just remediation.
What this means for you — Researcher:Volexity's timeline shows a multi-week zero-day exploitation window before public disclosure — worth digging into the chained root-access mechanics and whether Inc's tooling overlaps with other actors seen in the same window.