MILPITAS, Calif., 11 AUG 2026 — CISA gave federal agencies three days to patch two SonicWall flaws in July. A month later, ransomware crews are using them at scale, and the organisations that patched on time may still be exposed.

The pair is CVE-2026-15409, a server-side request forgery rated CVSS 10, and CVE-2026-15410, a command injection rated 7.2. Chained, they let an unauthenticated attacker open a WebSocket tunnel to restricted services on an SMA1000 remote-access gateway and escalate to root.

The timeline

22 JuneExploited as zero-days by the group tracked as UTA0533, deploying custom malware.
14 JulyBoth CVEs added to CISA's Known Exploited Vulnerabilities catalogue. Federal deadline: 17 July.
Mid-JulySonicWall releases fixes.
AugustINC Ransomware becomes the dominant actor chaining the pair. 885 victims on its leak site.

Shadowserver still tracks more than 380 SMA1000 instances exposed online. SonicWall's original advisory has not been updated to reflect the ransomware activity; the confirmation came from CISA.

Three days, again

We are talking about the remediation window because this is the second three-day CISA deadline we have covered in a fortnight.

On 4 August we reported that CISA's KEV deadlines have collapsed — three days for N-able N-central, where a year earlier 92% of KEV entries carried three weeks. This is the same pattern from a month earlier: KEV on 14 July, remediate by the 17th.

A three-day window is an accurate statement of urgency and an impossible instruction for most organisations. A remote-access gateway is the device every other worker reaches the network through; taking it down is a change-control conversation, not a Tuesday afternoon. Federal agencies have the mandate to do it anyway. A regional hospital or a water utility has the same exposure and none of the mandate, budget or staff.

Patching may not be remediation here

Even teams that patched on time are likely to miss the most important step.

An attacker who reached root on a gateway before the patch had access to the material it holds to authenticate your workforce. Reporting on this campaign describes theft of multi-factor authentication seeds among the post-exploitation activity.

If that happened on your device, applying the fix closes the door and leaves the attacker holding keys cut before you changed the lock. Seeds do not expire when you patch. Neither do stored credentials, session material or configuration secrets.

Anyone who ran an unpatched SMA1000 between late June and mid-July has a longer checklist than just patching: rotate MFA seeds and re-enrol users, rotate any credential the appliance stored, invalidate sessions, and go through authentication logs for the window looking for successful logins that do not match a human being's movements.

An organisation that patched inside the three-day window but did nothing else has closed the entry route while leaving the attacker's access intact — arguably a worse position than knowing you are vulnerable.

Why gateways keep being the target

The pattern across recent incidents is not about vendor quality; it is about the target.

The Polish grid intrusion began at an internet-facing Fortinet VPN and firewall. The water-utility campaign turned on devices reachable from the internet. This one is a remote-access gateway. By design, these appliances sit at the network boundary, hold credentials, and must be reachable from anywhere. They are the one class of device an organisation cannot simply take offline.

They are also frequently the least-instrumented thing in the estate. Endpoint detection runs on laptops and servers; the appliance is a black box from a vendor, and the logs it produces often go nowhere anybody reads.

What to do this week

Patch if you have not. Then treat the exposure window as an incident rather than a maintenance task, and work the list above.

If you cannot confirm your gateway's patch status and exposure between 22 June and mid-July, finding out is worth an hour of someone's time today. The answer determines if the rest of this checklist applies to you.

And check where the appliance's logs go. If the logs stay on the appliance, you cannot answer the question above. That is a problem to fix before the next incident.

What to watch

Whether SonicWall updates its advisory to reflect ransomware exploitation. Right now a customer reading the vendor's own page gets a less urgent picture than a customer reading CISA's.

Whether the exposed count falls. That more than 380 instances are still visible a month after a maximum-severity flaw went into KEV shows how little of this advice is reaching the right people.

And whether INC's victim list keeps growing at the current rate, which would suggest the initial access is still working somewhere.