Security researchers this week confirmed that INC Ransomware has become the dominant threat actor exploiting a pair of SonicWall SMA 1000 series vulnerabilities, with attacks accelerating sharply since the start of August. The flaws — CVE-2026-15409 (a maximum-severity 10.0) and CVE-2026-15410 — let an unauthenticated attacker connect to restricted services on the device and escalate straight to root access, no login required. SonicWall shipped fixes back in mid-July, but researchers at Volexity say exploitation was already happening quietly weeks before that, and the gang has now listed multiple fresh victims on its dark web leak site, with the most recent added on 2 August.
SMA 1000 devices are remote-access VPN appliances — exactly the kind of “boring” infrastructure that keeps staff connected to the office network from home or on the road, and exactly the kind of device that rarely gets checked once it’s set up and working. That combination is precisely why it’s attractive to attackers: it sits on the internet-facing edge of your network, and a successful compromise hands over a foothold deep inside, not just access to one app.
Why this one deserves a same-day check, not a someday one
Unauthenticated, root-level compromise is about as bad as a vulnerability gets — it means an attacker doesn’t need a password, a phishing click, or an insider mistake to get in, just a device that’s reachable and unpatched. The gap between “patch available” and “patch applied” is exactly where INC Ransomware is operating right now, and the pace of new victims being listed shows they’re actively working through that gap rather than sitting on the exploit. If your business, or an IT provider acting on your behalf, manages a SonicWall SMA appliance for remote access, this is not a “get to it next sprint” item.
What to check today
Start by confirming whether you or your IT provider run a SonicWall SMA 1000 series device, and if so, which firmware version it’s on — SonicWall’s mid-July advisory lists the patched versions, and anything older needs updating immediately. If patching has already happened, don’t stop there: given researchers observed exploitation before the fix was even public, it’s worth asking whoever manages the device to check logs for suspicious WebSocket connections or unexpected admin activity in the weeks before you patched. If you can’t answer these questions yourself, that’s a sign your remote-access infrastructure needs a proper technical review rather than a “we think it’s fine” assumption. CoolCoding can audit exactly this kind of edge infrastructure and get patching on a proper schedule instead of a reactive one.
It’s also worth asking a broader question while you’re at it: is a SonicWall SMA device still the right tool for remote access in 2026, or is it legacy kit that’s been quietly ageing on the network edge since it was installed? Appliance-based VPNs are a recurring target precisely because they’re internet-facing, infrequently reviewed, and expensive to replace on a whim — which is exactly why attackers keep coming back to them across different vendors, year after year.
If you’re not sure whether you’ve already been hit
Root-level compromise doesn’t always announce itself immediately — attackers frequently sit quietly inside a network for days or weeks before deploying ransomware, using that time to map out what’s valuable and where your backups live. If you’ve had any unexplained account activity, unfamiliar admin logins, or slow/odd device behaviour on your network recently, it’s worth treating that as a signal worth investigating rather than dismissing. KeepSafe monitors for exactly this kind of exposure — flagging when your business’s credentials or systems show up somewhere they shouldn’t, so a quiet compromise doesn’t stay quiet until it’s a ransom note.
The takeaway
A single unpatched VPN appliance is all INC Ransomware needs right now, and they’re moving fast. If SonicWall SMA is part of your setup, checking the firmware version today is a five-minute job that beats discovering the alternative the hard way.