# SonicWall vulnerabilities & exploitation

**CISA KEV** · **Ransomware**

> As of 2026-10-05, Threadlinqs tracks 7 SonicWall CVEs, 7 in the CISA Known Exploited Vulnerabilities catalog, 3 used in ransomware campaigns, linked to 30 tracked threat campaigns and 12 named threat actors.

**Data as of:** 2026-10-05

## Exploitation timeline

Threadlinqs has recorded 7 SonicWall CVEs published between 2021-12-15 and 2026-09-15. The busiest month was 2026-07 (2 new CVEs). 7 of them (100%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 7 of 7 tracked SonicWall CVEs.

- [CVE-2024-53704](https://intel.threadlinqs.com/cve/CVE-2024-53704) — HIGH 8.2 · KEV · Ransomware · EPSS 95.1% · 2025-01-09
- [CVE-2021-44228](https://intel.threadlinqs.com/cve/CVE-2021-44228) — CRITICAL 10 · KEV · Ransomware · EPSS 94.4% · 2021-12-10
- [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410) — HIGH 7.2 · KEV · EPSS 76.3% · 2026-07-14
- [CVE-2024-40766](https://intel.threadlinqs.com/cve/CVE-2024-40766) — CRITICAL 9.3 · KEV · Ransomware · EPSS 3.5% · 2024-08-23
- [CVE-2026-83549](https://intel.threadlinqs.com/cve/CVE-2026-83549) — HIGH 7.8 · KEV · EPSS 0.9% · 2026-09-01
- [CVE-2026-83548](https://intel.threadlinqs.com/cve/CVE-2026-83548) — CRITICAL 10 · KEV · EPSS 0.3% · 2026-09-01
- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409) — CRITICAL 10 · KEV · 2026-07-14

## Products affected

Threadlinqs normalises CPE and CNA product records across all 7 CVEs; 3 distinct SonicWall products are affected. The most frequently affected:

- SMA1000 — 4 CVEs
- SonicOS — 2 CVEs
- Email Security — 1 CVE

## Threat activity

30 tracked threat campaigns reference SonicWall products or exploit SonicWall CVEs; the 25 most recent are listed.

- [The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira, REDBIKE, AGENDA)](https://intel.threadlinqs.com/threat/TL-2026-2852) — HIGH — 2026-10-03
- [Eclypsium InfraTrust Report: Mass Active Exploitation of Network Management Systems (Cisco FMC/ISE CVE-2026-20079, CVE-2026-76460; SonicWall SMA 1000 CVE-2026-83548/83549; Linux Kernel CopyFail CVE-2026-31431)](https://intel.threadlinqs.com/threat/TL-2026-2630) — CRITICAL — 2026-09-23
- [Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker, Qilin, INC Ransom, Lynx) Abuse Dual-Use Tools and Exploit SonicWall, Gladinet CentreStack, and FortiGate Devices](https://intel.threadlinqs.com/threat/TL-2026-2517) — HIGH — 2026-09-15
- [DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD Files with Defense Mil-Spec References](https://intel.threadlinqs.com/threat/TL-2026-2364) — CRITICAL — 2026-09-06
- [Chinese-Speaking Operator "Nie" Uses SecFlow AI Orchestration Framework (Claude, Qwen, DeepSeek) and GLUTTON Steganographic Webshell in Multi-Country Espionage Campaign](https://intel.threadlinqs.com/threat/TL-2026-2325) — HIGH — 2026-09-04
- [SonicWall SMA1000 Chained Vulnerabilities (CVE-2026-83548, CVE-2026-83549) Exploited in the Wild](https://intel.threadlinqs.com/threat/TL-2026-2307) — CRITICAL — 2026-09-03
- [Edge Infrastructure Under Siege: Tenable and SentinelOne Datasets Reveal Convergent Nation-State and Criminal Exploitation of Perimeter Devices](https://intel.threadlinqs.com/threat/TL-2026-2153) — HIGH — 2026-08-26
- [2026 Ransomware Surge Targeting US Organizations: Identity-First Compromise, BYOVD, and Living-Off-the-Cloud Exfiltration (Qilin, Akira, Clop, INC Ransom, Play, DragonForce, Sinobi)](https://intel.threadlinqs.com/threat/TL-2026-2125) — HIGH — 2026-08-23
- [LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp)](https://intel.threadlinqs.com/threat/TL-2026-2094) — HIGH — 2026-08-21
- [Akira Ransomware Affiliate Forces Windows Safe Mode Reboot to Disable EDR, Exfiltrates Data via AnyDesk/WinRAR/s5cmd but Fails to Encrypt](https://intel.threadlinqs.com/threat/TL-2026-2010) — HIGH — 2026-08-13
- [Akira Ransomware Reboots Victims into Safe Mode to Blind EDR and Windows Defender](https://intel.threadlinqs.com/threat/TL-2026-2062) — HIGH — 2026-08-12
- [GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting Business Managers: 351 Victims Across 334 Organizations](https://intel.threadlinqs.com/threat/TL-2026-1917) — HIGH — 2026-08-06
- [QuoIntelligence Weekly Snapshot W32 2026: DOUBLECUP ClickFix loader, UTA0533 SonicWall SMA1000 zero-day chain (CVE-2026-15409/15410), Greatness AiTM/device-code PhaaS, EtherRAT blockchain C2](https://intel.threadlinqs.com/threat/TL-2026-2893) — HIGH — 2026-08-06
- [Actively Exploited SonicWall SMA1000 Zero-Days (CVE-2026-15409, CVE-2026-15410) Chained for Full Appliance Takeover Alongside Microsoft July 2026 Patch Tuesday (570 CVEs, 3 Zero-Days incl. SharePoint & AD FS EoP)](https://intel.threadlinqs.com/threat/TL-2026-1451) — CRITICAL — 2026-07-17
- [SonicWall SMA1000 Zero-Days (CVE-2026-15409, CVE-2026-15410) Chained in Active Attacks, Assessed Ransomware Precursor](https://intel.threadlinqs.com/threat/TL-2026-1462) — CRITICAL — 2026-07-17
- [SonicWall SMA1000 Zero-Day Vulnerabilities Chained for Full Appliance Compromise (CVE-2026-15409, CVE-2026-15410)](https://intel.threadlinqs.com/threat/TL-2026-1396) — CRITICAL — 2026-07-16
- [SonicWall SMA1000 Zero-Day Vulnerabilities (CVE-2026-15409, CVE-2026-15410) Actively Exploited in Tandem](https://intel.threadlinqs.com/threat/TL-2026-1357) — CRITICAL — 2026-07-15
- [SonicWall SMA1000 Zero-Days CVE-2026-15409 (Unauthenticated SSRF, CVSS 10.0) and CVE-2026-15410 (Post-Auth Code Injection, CVSS 7.2) Chained for Root Compromise, Actively Exploited](https://intel.threadlinqs.com/threat/TL-2026-1382) — CRITICAL — 2026-07-15
- [CVE-2026-15409 / CVE-2026-15410: SonicWall SMA 1000 Zero-Day SSRF and Code Injection Chained for Unauthenticated RCE](https://intel.threadlinqs.com/threat/TL-2026-1385) — CRITICAL — 2026-07-15
- [SonicWall SMA1000 SSRF (CVE-2026-15409, CVSS 10.0) Chained With Appliance Management Console Command Injection (CVE-2026-15410, CVSS 7.2) Under Active Zero-Day Exploitation](https://intel.threadlinqs.com/threat/TL-2026-1390) — CRITICAL — 2026-07-15
- [US Treasury (OFAC) and UK Sanction First VPN Service (1VPNS), Administrator Dmytro Rashevskyi, and Cryptor Seller Yevgeniy Silayev for Enabling Anubis and Sinobi Ransomware Operations](https://intel.threadlinqs.com/threat/TL-2026-1316) — HIGH — 2026-07-14
- [SonicWall SMA1000 SSRF (CVE-2026-15409) and Code Injection (CVE-2026-15410) Actively Exploited in Tandem](https://intel.threadlinqs.com/threat/TL-2026-1323) — CRITICAL — 2026-07-14
- [SonicWall SMA1000 SSRF (CVE-2026-15409) and Post-Auth Code Injection (CVE-2026-15410) Exploited as Zero-Days](https://intel.threadlinqs.com/threat/TL-2026-1335) — CRITICAL — 2026-07-14
- [SEO Poisoning Supply Chain Campaign Distributing Akira Ransomware via Trojanized Enterprise Software](https://intel.threadlinqs.com/threat/TL-2026-1004) — CRITICAL — 2026-06-30
- [Aquatic Panda (Earth Lusca) APT - Log4Shell Exploitation and Multi-Platform Backdoor Campaigns Targeting 17 Countries](https://intel.threadlinqs.com/threat/TL-2026-0986) — CRITICAL — 2026-06-28

## Threat actors targeting SonicWall

Named threat actors attributed to campaigns that involve SonicWall products or CVEs, with the number of linked campaigns:

- [Akira](https://intel.threadlinqs.com/actor/Akira) — 5 campaigns
- [Storm-1567](https://intel.threadlinqs.com/actor/Storm-1567) — 5 campaigns
- [DragonForce](https://intel.threadlinqs.com/actor/DragonForce) — 3 campaigns
- [Clop](https://intel.threadlinqs.com/actor/Clop) — 2 campaigns
- [INC Ransom](https://intel.threadlinqs.com/actor/INC%20Ransom) — 2 campaigns
- [INC Ransom - G1032](https://intel.threadlinqs.com/actor/INC%20Ransom%20-%20G1032) — 2 campaigns
- [Sinobi](https://intel.threadlinqs.com/actor/Sinobi) — 2 campaigns
- [UTA0533](https://intel.threadlinqs.com/actor/UTA0533) — 2 campaigns
- [Earth Lusca](https://intel.threadlinqs.com/actor/Earth%20Lusca) — 1 campaign
- [Greatness PhaaS Operators](https://intel.threadlinqs.com/actor/Greatness%20PhaaS%20Operators) — 1 campaign
- [INC Ransomware](https://intel.threadlinqs.com/actor/INC%20Ransomware) — 1 campaign
- [MedusaLocker](https://intel.threadlinqs.com/actor/MedusaLocker) — 1 campaign

## How to prioritise SonicWall patching

This order follows the data Threadlinqs holds for SonicWall, not a generic severity checklist:

- 7 of 7 SonicWall CVEs (100%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with [CVE-2024-53704](https://intel.threadlinqs.com/cve/CVE-2024-53704), [CVE-2021-44228](https://intel.threadlinqs.com/cve/CVE-2021-44228), [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410).
- 3 CVEs are known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- 4 CVEs score Critical and 3 High on CVSS v3 (maximum 10, average 8.9); sequence these after KEV and high-EPSS items.
- 3 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/sonicwall
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
