Exploitation timeline
Threadlinqs has recorded 7 SonicWall CVEs published between and . The busiest month was 2026-07 (2 new CVEs). 7 of them (100%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.
Most exploited vulnerabilities
Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 7 of 7 tracked SonicWall CVEs.
- CVE-2024-53704high 8.2KEVRansomwareEPSS 95.1%
- CVE-2021-44228critical 10KEVRansomwareEPSS 94.4%
- CVE-2026-15410high 7.2KEVEPSS 76.3%
- CVE-2024-40766critical 9.3KEVRansomwareEPSS 3.5%
- CVE-2026-83549high 7.8KEVEPSS 0.9%
- CVE-2026-83548critical 10KEVEPSS 0.3%
- CVE-2026-15409critical 10KEV
Products affected
Threadlinqs normalises CPE and CNA product records across all 7 CVEs; 3 distinct SonicWall products are affected. The most frequently affected:
- SMA1000 4 CVEs
- SonicOS 2 CVEs
- Email Security 1 CVE
Threat activity
30 tracked threat campaigns reference SonicWall products or exploit SonicWall CVEs; the 25 most recent are listed.
- The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira, REDBIKE, AGENDA)HIGH
- Eclypsium InfraTrust Report: Mass Active Exploitation of Network Management Systems (Cisco FMC/ISE CVE-2026-20079, CVE-2026-76460; SonicWall SMA 1000 CVE-2026-83548/83549; Linux Kernel CopyFail CVE-2026-31431)CRITICAL
- Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker, Qilin, INC Ransom, Lynx) Abuse Dual-Use Tools and Exploit SonicWall, Gladinet CentreStack, and FortiGate DevicesHIGH
- DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD Files with Defense Mil-Spec ReferencesCRITICAL
- Chinese-Speaking Operator "Nie" Uses SecFlow AI Orchestration Framework (Claude, Qwen, DeepSeek) and GLUTTON Steganographic Webshell in Multi-Country Espionage CampaignHIGH
- SonicWall SMA1000 Chained Vulnerabilities (CVE-2026-83548, CVE-2026-83549) Exploited in the WildCRITICAL
- Edge Infrastructure Under Siege: Tenable and SentinelOne Datasets Reveal Convergent Nation-State and Criminal Exploitation of Perimeter DevicesHIGH
- 2026 Ransomware Surge Targeting US Organizations: Identity-First Compromise, BYOVD, and Living-Off-the-Cloud Exfiltration (Qilin, Akira, Clop, INC Ransom, Play, DragonForce, Sinobi)HIGH
- LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp)HIGH
- Akira Ransomware Affiliate Forces Windows Safe Mode Reboot to Disable EDR, Exfiltrates Data via AnyDesk/WinRAR/s5cmd but Fails to EncryptHIGH
- Akira Ransomware Reboots Victims into Safe Mode to Blind EDR and Windows DefenderHIGH
- GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting Business Managers: 351 Victims Across 334 OrganizationsHIGH
- QuoIntelligence Weekly Snapshot W32 2026: DOUBLECUP ClickFix loader, UTA0533 SonicWall SMA1000 zero-day chain (CVE-2026-15409/15410), Greatness AiTM/device-code PhaaS, EtherRAT blockchain C2HIGH
- Actively Exploited SonicWall SMA1000 Zero-Days (CVE-2026-15409, CVE-2026-15410) Chained for Full Appliance Takeover Alongside Microsoft July 2026 Patch Tuesday (570 CVEs, 3 Zero-Days incl. SharePoint & AD FS EoP)CRITICAL
- SonicWall SMA1000 Zero-Days (CVE-2026-15409, CVE-2026-15410) Chained in Active Attacks, Assessed Ransomware PrecursorCRITICAL
- SonicWall SMA1000 Zero-Day Vulnerabilities Chained for Full Appliance Compromise (CVE-2026-15409, CVE-2026-15410)CRITICAL
- SonicWall SMA1000 Zero-Day Vulnerabilities (CVE-2026-15409, CVE-2026-15410) Actively Exploited in TandemCRITICAL
- SonicWall SMA1000 Zero-Days CVE-2026-15409 (Unauthenticated SSRF, CVSS 10.0) and CVE-2026-15410 (Post-Auth Code Injection, CVSS 7.2) Chained for Root Compromise, Actively ExploitedCRITICAL
- CVE-2026-15409 / CVE-2026-15410: SonicWall SMA 1000 Zero-Day SSRF and Code Injection Chained for Unauthenticated RCECRITICAL
- SonicWall SMA1000 SSRF (CVE-2026-15409, CVSS 10.0) Chained With Appliance Management Console Command Injection (CVE-2026-15410, CVSS 7.2) Under Active Zero-Day ExploitationCRITICAL
- US Treasury (OFAC) and UK Sanction First VPN Service (1VPNS), Administrator Dmytro Rashevskyi, and Cryptor Seller Yevgeniy Silayev for Enabling Anubis and Sinobi Ransomware OperationsHIGH
- SonicWall SMA1000 SSRF (CVE-2026-15409) and Code Injection (CVE-2026-15410) Actively Exploited in TandemCRITICAL
- SonicWall SMA1000 SSRF (CVE-2026-15409) and Post-Auth Code Injection (CVE-2026-15410) Exploited as Zero-DaysCRITICAL
- SEO Poisoning Supply Chain Campaign Distributing Akira Ransomware via Trojanized Enterprise SoftwareCRITICAL
- Aquatic Panda (Earth Lusca) APT - Log4Shell Exploitation and Multi-Platform Backdoor Campaigns Targeting 17 CountriesCRITICAL
Threat actors targeting SonicWall
Named threat actors attributed to campaigns that involve SonicWall products or CVEs, with the number of linked campaigns:
How to prioritise SonicWall patching
This order follows the data Threadlinqs holds for SonicWall, not a generic severity checklist:
- 7 of 7 SonicWall CVEs (100%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with CVE-2024-53704, CVE-2021-44228, CVE-2026-15410.
- 3 CVEs are known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- 4 CVEs score Critical and 3 High on CVSS v3 (maximum 10, average 8.9); sequence these after KEV and high-EPSS items.
- 3 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.
About this data
Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.