Published on 13 August 2026
Ransomware groups are currently actively exploiting two security vulnerabilities in SonicWall SMA1000 appliances – and one of the two flaws reaches the highest possible severity rating of CVSS 10.0. The US cybersecurity agency CISA has officially classified both vulnerabilities, CVE-2026-15409 and CVE-2026-15410, as being used in ransomware campaigns. As of the reporting date on 10 August 2026, according to an analysis by the Shadowserver Foundation, more than 380 SMA1000 appliances were reachable from the internet – how many of them have already been patched or already compromised is unknown.
If your company runs such an appliance – or an IT service provider operates one to access your systems – you should read this article to the end and take action today.
Affected is SonicWall's Secure Mobile Access 1000 series (SMA1000). These are not web servers or content management systems, but VPN and remote access appliances – that is, devices at the network edge through which employees or service providers securely connect to the corporate network from the outside. Precisely because such devices sit at the interface between the internet and the internal network, a takeover is especially dangerous.
SonicWall published security updates on 14 July 2026 (advisory SNWLID-2026-0008) and confirmed active exploitation. The PSIRT (the vendor's own security team) puts it this way:
„SonicWall PSIRT has investigated multiple cases indicating the active exploitation of the vulnerabilities described in this advisory.“ – SonicWall PSIRT
CISA added both vulnerabilities to its KEV catalogue that same day – a register of flaws that are demonstrably being actively attacked. In the current detail views, both CVEs are additionally flagged as "Known To Be Used in Ransomware Campaigns? Known".
The attackers use a chain of two vulnerabilities that build on each other.
This is a so-called Server-Side Request Forgery (SSRF) – a flaw in which an attacker makes the appliance issue internal requests on their behalf. It resides in the WorkPlace interface and requires no login and no user interaction. According to the forensic analyses by the security firms Volexity and Rapid7, an attacker can use the /wsproxy path to establish a so-called WebSocket tunnel (a persistent connection) to services that should actually only be reachable locally on the device itself – for instance the internal database service on port 1050 or the SMA Control service on port 8188. The intended separation between the public interface and internal management services is thereby undermined.
The second flaw (CVSS 7.2 according to the vendor) sits in the workflow for removing hotfixes in the management console. In the observed attack chain, it is exploited via a path traversal vulnerability (breaking out of an intended directory) to execute a script as root – that is, with the highest system privileges. Combined, this means: an attack from the internet can lead to a complete takeover of the appliance.
The BSI confirms that a proof-of-concept (a publicly available sample attack code) has already been published for CVE-2026-15409 – which is why further exploitation is to be expected.
The security researchers at Volexity documented on examined devices, among other things, the malware KNUCKLEBALL, ROOTRUN/xzfind, Suo5 and ORANGETAIL, as well as manipulated startup scripts. Rapid7 additionally observed the theft of high-value credentials, active session data and MFA seed configurations (the basis for two-factor codes), followed by lateral movement into the internal network. The Rapid7 MDR team summarises:
„Both vulnerabilities are being actively exploited in the wild.“ – Rapid7 MDR Team
Important for context: these are observations from individual incident response cases. They do not prove that every unpatched appliance has already been compromised – but they do show how dangerous the real-world attack is.
The security researchers at Volexity observed the earliest indication of compromise as early as 22 June 2026 – that is, roughly three weeks before the vendor's public disclosure. This makes it a so-called zero-day exploitation, in which attackers exploit the flaw before a patch exists.
Affected, according to the vendor, are the models SMA 6210, SMA 7210, SMA 8200v as well as CMS installations on all hypervisors in certain firmware versions of the 12.4.3 and 12.5.0 lines. Not affected, according to SonicWall, are the SSL VPN features on SonicWall firewalls and the SMA 100 product family.
For pure website operators without an SMA1000, there is no direct technical exposure from these CVEs. The flaws affect neither WordPress nor a general web server. Indirectly, an SME can nevertheless be at risk: namely when an SMA1000 access point operated by the company itself or by a service provider paves the way to hosting, website administration, customer data, backups, email or Active Directory.
The crucial first question is therefore not "Is our website affected?" but: "Is there an SMA1000 appliance in our access path – and has it been updated to a remediated hotfix level?"
extraweb_access.log for successful accesses (HTTP 200) to /__api__/login or /__api__/logout as well as for /wsproxy entries with HTTP 101 and suspicious host parameters – especially with 0.0.0.0, localhost or ::ffff:127.0.0.1.ctrl-service.log for calls to remove_hotfix with path traversal and the file /var/lib/unit/conf.json for illegitimate routes. As part of a qualified forensic investigation, look for unexpected files in /tmp and /var/tmp.SonicWall published platform hotfixes on 14 July 2026. There is no workaround. Because of the confirmed active exploitation, mere patching is not enough – the BSI requires an assume-breach approach:
„Betreiber sollten von einer Kompromittierung ausgehen (‚Assume Breache‘), solange sie nicht das Gegenteil nachweisen können.“ – BSI
A compromised appliance is not automatically a reportable data breach. It does become one, however, if it leads to unauthorised access, disclosure, loss, alteration or unavailability of personal data. The European Data Protection Board explicitly names ransomware as a possible example.
Important: the 72-hour deadline under Art. 33 GDPR runs from the moment the breach becomes known – not from the patch date. Insofar as there is likely to be a risk to the rights and freedoms of natural persons, the competent supervisory authority must be notified without undue delay, if possible within 72 hours. Where a high risk is likely, the affected individuals must additionally be informed (Art. 34 GDPR). Processors must inform the controller without undue delay.
Art. 32 GDPR additionally requires a level of security appropriate to the risk. Breaches of Art. 32 as well as of the notification obligations can be sanctioned under Art. 83(4) GDPR with fines of up to €10 million or up to 2% of worldwide annual turnover – whichever is higher. The actual legal consequence always depends on the individual case; a concrete fine prognosis is not possible.
To illustrate the relevance of Art. 32 – but explicitly not as a benchmark for this case or for individual SMEs – German comparison cases serve as examples: in 2019 the BfDI imposed a fine of €9.55 million on 1&1 Telecom, and in 2025 two fines on Vodafone totalling €45 million, of which €30 million was for security deficiencies in the authentication process. BfDI chief Prof. Dr. Louisa Specht-Riemenschneider summarises the line as follows:
„Ohne IT-Investitionen drohen Sicherheitsvorfälle und auch Sanktionen der Datenschutzaufsicht. Daher mein Aufruf: Investieren statt Riskieren!“ – Prof. Dr. Louisa Specht-Riemenschneider, BfDI
For organisations with an internet-exposed, unpatched SMA1000, the priority is critical: the entry point via CVE-2026-15409 requires no authentication, and the second flaw enables a complete takeover in the documented chain. CISA lists both CVEs as actively exploited and used in ransomware campaigns; the BSI expects further short-term exploitation of unpatched systems.
The overall context also calls for seriousness: the BSI's 2025 situation report cites 950 reported ransomware attacks in Germany for the period 1 July 2024 to 30 June 2025 and continues to assess ransomware in combination with data leaks as the source of the greatest damage.
The sources analysed do not provide reliable overall figures on compromised companies or affected personal data records specifically for these two CVEs. Only the number of exposed devices is known: more than 380.
These flaws do not affect your website directly – but possibly the access path to everything behind it. Anyone who operates or has operated an SMA1000 of models 6210, 7210 or 8200v must do two things today: apply the appropriate hotfix (12.4.3-03453+ or 12.5.0-02835+) and start a forensic compromise assessment. With active exploitation running since the end of June, a patch alone is not enough to feel safe.
If you do not run your own network operations, send a written enquiry to your IT and hosting service providers today: do they use SMA1000, and is the hotfix installed? In an emergency, this one question can determine data protection reporting obligations, the risk of fines and the survival of your systems.