KOM CLOUDSERVICE
All Insights

Ransomware Gangs Are Now Hitting SonicWall Remote Access. Patch Now.

CISA confirms ransomware crews are exploiting two SonicWall SMA1000 flaws. If your VPN runs on one, here's what to do this week.

CISA just confirmed that ransomware gangs are actively exploiting two SonicWall SMA1000 vulnerabilities, including one rated maximum severity. SonicWall patched these in mid July and warned even then that attackers were already using them. Now the crews behind the attacks aren’t just stealing data. They’re locking companies out and demanding money. If your remote access runs through one of these boxes, this is a today problem, not a someday problem.

Here’s what happened and why it matters to you even if you’ve never heard of an SMA1000.

What the SMA1000 actually is

The SonicWall SMA1000 is a secure remote access gateway. In plain terms, it’s the appliance that lets people log in to your internal network and applications from outside the office. If your staff work from home, connect from the road, or reach a line-of-business app over a VPN, there’s a decent chance something like this sits at the front door.

That’s exactly why attackers love it. It’s internet-facing by design, it holds the keys to your internal network, and a lot of companies set it up once and never touch it again.

The technique, in one breath

The two flaws are tracked as CVE-2026-15409 and CVE-2026-15410. The worst of them is a server-side request forgery bug, which means an attacker can trick the appliance into making requests it shouldn’t, reaching internal systems it was never supposed to expose. Chain that with the second flaw and you get a foothold on a device that’s already connected to everything inside.

The timeline is the part that should bother you. Incident response firm Volexity found a group exploiting these as early as June 22, weeks before SonicWall said a word publicly. They dropped custom malware on vulnerable appliances (researchers named the tools KNUCKLEBALL, Sou5, ROOTRUN, and ORANGETAIL). So this was a real zero-day being used quietly before anyone had a patch. CISA added both flaws to its Known Exploited Vulnerabilities list on July 14 and gave federal agencies three days to fix them. Three days. That’s how seriously they took it.

Now, weeks later, the ransomware crews have moved in. The security watchdog Shadowserver still counts over 380 of these appliances exposed on the internet. Some are already patched. Plenty are not.

Why a small business should care

You might be thinking this is enterprise gear, not your problem. Two reasons it may be.

First, the SMA1000 is common at Managed Service Providers, the companies some small businesses hire to run their IT. If your provider runs one and it’s unpatched, an attacker who gets in there can reach you. That’s not hypothetical. We’ve watched ransomware spread from a provider’s remote access tools straight into client networks.

Second, the pattern here is the pattern that keeps hitting small firms. An internet-facing device with a known hole, left unpatched, becomes the way in. It doesn’t matter whether it’s a SonicWall, a Fortinet, a Cisco VPN, or an old firewall in a closet. CISA’s fresh Gunra ransomware advisory this same week says it plainly: the number one action is to prioritize patching known exploited vulnerabilities in internet-facing systems, VPNs included. The gangs read the same advisories you do. They just act faster.

And once they’re in through a VPN appliance, MFA on your email won’t save you. They’re already past the front door, sitting on a device that trusts the whole network.

What to do this week

If you or your IT provider run a SonicWall SMA1000, do these in order:

  1. Apply SonicWall’s hotfix now. They released it in mid July. If you’re behind, you’ve been exposed the entire time attackers have been active. This is the single thing that closes the hole.

  2. Assume you may already be compromised, and check. Patching stops new entry. It does not evict someone who got in during the last few weeks. Look at the appliance logs, check for unexpected admin accounts or config changes, and watch for the malware families named above. If you can’t do this yourself, get someone who can.

  3. Ask your MSP directly: are your remote access appliances patched, and when. You’re allowed to ask this. A real answer with a date is a good sign. Vague reassurance is not.

  4. Reduce your exposure. Does that gateway need to be reachable from the entire internet? Usually it can be locked down to known locations or put behind stronger access controls. Fewer open doors, fewer break-ins.

  5. Confirm your backups are offline and tested. Ransomware’s whole business model is that you can’t recover without paying. Backups they can’t reach and encrypt are what break that model. Test a restore. A backup you’ve never restored is a guess.

For clients, this is the kind of thing we handle before it becomes a headline: keeping internet-facing gear patched, watching those devices with endpoint detection that catches malware before it spreads (that’s part of our cybersecurity work), and checking that the remote access door isn’t wide open. Most of the damage from bugs like these comes from the gap between “patch released” and “patch applied.” Closing that gap fast is the whole game.

If you’re not sure whether your remote access is exposed, or who’s responsible for patching it, that’s worth a quick conversation. Book a free 15-minute consult and we’ll help you find out where you stand.

Talk to the person who'll actually run your IT.

Book a free 15-minute consult. No sales pitch from a stranger, just a straight conversation about what your business needs.

Book your free consult

Or call (732) 701-7012

Monthly agreements, not multi-year lock-ins  ·  No call centers, ever