SonicWall SMA 1000 CVE-2026-15409: A CVSS 10.0 Flaw Exploited by INC Ransomware
> TL;DR: CVE-2026-15409 (CVSS 10.0) is an unauthenticated server-side request forgery (SSRF) flaw affecting SonicWall SMA 1000 VPN gateways. Chained with CVE-2026-15410 (code injection, CVSS 7.2), it enables root-level command execution, fully bypassing authentication. The INC ransomware group has been exploiting this zero-day since early August 2026 to compromise organizations worldwide, claiming over 885 victims.
The attack chain
Why stealing MFA seeds changes everything
The most critical part of this attack isn't the initial access, but the exfiltration of TOTP seeds. Unlike a password, resetting an MFA seed requires reconfiguring every user's authenticator app individually. A simple password change after an incident is not enough: if the seeds were stolen, the attacker can keep generating valid MFA codes even after password rotation.
What to do
/__api__/login or /wsproxy, unexpected changes to configuration files.The lesson for any internet-facing infrastructure
A VPN gateway is, by design, exposed to the internet and meant to be a legitimate entry point into the internal network. An unauthenticated flaw at this level grants near-total access with minimal effort. For any SaaS vendor exposing network infrastructure components (VPNs, gateways, load balancers), the same principle documented in our guide to TLS/DNS/BGP network flaws applies: these components deserve an audit and patch cycle just as rigorous as the application itself, since they're often the very first link in the attack chain.
What CleanIssue checks for
Our audits cover the exposure of internet-facing network infrastructure components, and test the robustness of MFA against a secrets-theft scenario, not just its mere presence.
Key takeaways
Building HR, payroll, or recruiting software? CleanIssue performs security audits for HR SaaS in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.
Related articles
Three adjacent analyses to keep exploring the same attack surface.
Cl0p, LockBit, ALPHV: The Modern Ransomware Ecosystem in 2026
Mapping the ransomware ecosystem in 2026: the RaaS model, major groups, their tactics, and the evolution toward pure extortion.
VMware vCenter CVE-2026-59310: China-Linked APT Exploits Critical Flaw, France in the Top 5 Victims
CVE-2026-59310 (CVSS 9.8), a path traversal flaw in VMware vCenter, has been exploited by a suspected China-nexus actor to deploy backdoors and a Babuk-derived ransomware. 361 compromised IPs across 47 countries, including 25 in France.
Microsoft IKE CVE-2026-33824: When an Autonomous AI Drives the Exploitation Campaign
CVE-2026-33824 (CVSS 9.8), a double-free flaw in Microsoft's IKE service, was exploited as part of a hacking campaign driven by the DeepSeek AI model via the Hermes Agent framework, targeting over 460 organizations largely autonomously.
Sources
Related services
If this topic maps to a real risk in your stack, these are the most relevant CleanIssue audits.