THE INC Ransomware group has been identified as the primary threat actor exploiting two significant vulnerabilities in SonicWall’s SMA1000 secure remote access appliances, designated as CVE-2026-15409 (CVSS 10) and CVE-2026-15410 (CVSS 7.2). These flaws allow unauthenticated remote attackers to gain root access via WebSocket tunnels. The vulnerabilities were publicly patched on July 14, 2026, after being exploited as zero-days since June 22, 2026.
Cybersecurity firms noted that threat actors leveraged these vulnerabilities to access internal networks and harvest credentials. Victims, including private and government organizations across multiple countries, have reported receiving unsolicited communications from individuals posing as ransomware negotiators. Security experts recommend urgent patching of affected systems and conducting thorough threat assessments.