Vendor
SonicWall
- First Reported
- Jul 17, 2026
- Latest Reported
- Oct 7, 2026
Reported Context (6)
- SonicWall warns of max severity SSRF flaw in SMA1000 gateways SonicWall patches maximum-severity SSRF flaw in SMA1000 gateways
- two separate VPS providers, AS55286 and AS16276, used to facilitate initial access via exploitation of SonicWall appliances, aligning with broader industry reporting of Akira affiliates targeting SonicWall SSL VPN Team Cymru Details Ransomware Infrastructure Trends Across 20+ Investigations
- that the incident is linked to an actor performing mass exploitation of CVE-2026-15409 against SonicWall SMA1000 appliances. The operator gained command execution on appliances, extracted configurations, and Hunt.io Links UK Council Attack to SonicWall SMA1000 Exploitation Campaign
- On September 1, 2026, SonicWall disclosed two vulnerabilities in SonicWall SMA1000 appliances. Models 6210, 7210, and 8200v are affected. SonicWall SMA1000 Vulnerabilities CVE-2026-83548 and CVE-2026-83549 Exploited in the Wild
- a further four cases through analysts’ investigations: a Cursor-assisted detection-evasion case, a SonicWall SMA ransomware intrusion, a custom Slack-controlled RAT built with an AI coding agent, and a fake Claude Sophos Finds Fake AI Installers Dominated Malware Cases
CVE (6)
Malware (9)
People (2)
Threat Actors (13)
MITRE ATT&CK (37)
Vendors (9)
Products (28)
Tools (28)
Industries (10)
Countries (12)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.