September 11, 2026
- SonicWall SMA1000 (CVE-2026-15409) was chained from SSRF into RCE in the appliance's Erlang service and on to automated DCSync from the appliance itself, in an intrusion at a UK council (Hunt.io).
· Exploitation in the Wild
in Four Hours to First Victim: AI Agents Ran a Global PaperCut Campaign
July 18, 2026
- SonicWall SMA exploitation attributed to UTA0533 and Inc ransomware — Volexity details root access, staged scripts, and webshell implants via chained zero-days; Horizon3 maps CVE-2026-15409/CVE-2026-15410 (SSRF + post-auth code injection) on SMA1000 (Volexity, Horizon3), with Inc Ransomware named as an exploiting actor (Dark Reading). Continues this week's SonicWall thread with fresh attribution.
· Threat Activity
in A Pre-Auth RCE Lands in WordPress Core, Proof-of-Concept and All
July 17, 2026
- SonicWall SMA1000 SSL-VPN appliances are under broad-scale exploitation via CVE-2026-15409, with watchTowr's honeypot network logging activity from ~03:00 UTC leveraging publicly available PoC code (watchTowr); Rapid7 published a working non-root RCE PoC (GitHub). This follows the SMA1000 zero-days added to CISA KEV earlier this week (earlier coverage). watchTowr's advice: patch immediately and hunt logs for successful exploitation.
· Vulnerabilities & Exploits
in Live SonicWall Exploitation, a New C2 Release, and AI Agents Tricked Into Running Attacker Commands
July 16, 2026
- Two SonicWall SMA1000 zero-days are under active exploitation and now in CISA's KEV catalog. CVE-2026-15409 (CVSS 10.0) is an unauthenticated SSRF, and CVE-2026-15410 can enable arbitrary command execution; patch immediately. Sweden's national CERT has amplified the advisory. CERT-SE, The Hacker News, BleepingComputer
· Vulnerabilities & Exploits
in Relay Chains, Bind-Link Blindspots, and a Wave of Live Zero-Days