Picture the IT lead at a 90-person firm on a Tuesday in late June. Everything looks normal. Employees are logging in through the VPN from home, from the road, from client sites. The remote-access appliance at the edge of the network is doing exactly what it’s supposed to do. What nobody in that building knows is that attackers have already been inside that appliance for days, quietly collecting credentials and setting up for a ransomware payload.
That’s not a hypothetical. That’s roughly the timeline SonicWall and security researchers described this month, and it’s a good reminder that the box sitting at the edge of your network is the first thing an attacker reaches for.
What actually happened
On July 14, SonicWall disclosed two zero-day vulnerabilities in its SMA 1000 Series remote-access appliances. According to BleepingComputer, one of them, tracked as CVE-2026-15409, carries a CVSS score of 10.0, the maximum possible severity. The second, CVE-2026-15410, chains with it.
The uncomfortable part is the timeline. BleepingComputer reported that attackers linked to the Inc ransomware-as-a-service group had already been silently exploiting the flaw chain since at least June 22, more than three weeks before a patch existed. During that window, the attackers were harvesting credentials and staging ransomware. In other words, the disclosure and the patch came after the attacks were already underway, not before.
CISA moved quickly. According to BleepingComputer, the agency added both CVEs to its Known Exploited Vulnerabilities catalog and set a July 17 remediation deadline for federal agencies. When CISA puts a three-day fuse on a fix, it is telling you the exploitation is real and ongoing, not theoretical.
A CVSS 10.0 on a remote-access appliance is about as bad as a rating gets. It generally means the flaw can be exploited over the network, requires no valid credentials, and needs little to no interaction from anyone on your side. The appliance is designed to be reachable from the public internet, because that’s how remote workers connect to it. So a maximum-severity flaw in that specific kind of device means an attacker can potentially reach it, break it, and use it without ever tricking one of your employees into clicking anything.
Why this matters to your business
Here’s the pattern worth understanding, because it repeats far beyond this one vendor.
Edge remote-access appliances, VPN concentrators, and secure gateways are the softest entry point for mid-sized organizations for three reasons. First, they’re exposed to the internet by design, so attackers can find them with automated scanning. Second, they run vendor firmware that most in-house teams can’t inspect the way they’d inspect a server, so a flaw stays invisible until the vendor discloses it. Third, they sit at a trusted position in the network. Once an attacker controls the appliance every remote user authenticates through, they can collect credentials and move deeper without setting off the usual alarms.
Ransomware-as-a-service groups like Inc understand this. They don’t need to phish 90 employees and hope one takes the bait. They need one unpatched appliance facing the internet. Credentials harvested from that appliance become the keys to email, file shares, and eventually the backups. By the time anyone notices, the staging is done.
For a mid-sized organization, the business exposure isn’t abstract. It’s the possibility of downtime measured in days, a ransom demand, regulatory notification obligations depending on what data was reached, and the slow, expensive work of rebuilding trust with clients afterward. The appliance that felt like a convenience becomes the thing that took the company offline.
And the zero-day window is the part you can’t fully control. For those three-plus weeks in June, there was no patch to apply. That’s exactly why the response can’t only be “patch when the vendor tells us to.” It has to include knowing what you have exposed, watching it, and having a plan for the days before a fix exists.
What to do this week
You don’t need to solve remote-access security forever this week. You need to answer a few specific questions and act on the answers.
-
Find out if you run SonicWall SMA 1000 Series appliances. This sounds obvious, and it’s the step most organizations skip. Ask your IT team or provider for a plain answer: do we have any SMA 1000 devices, what firmware version, and are they reachable from the internet? If you have them, applying SonicWall’s patch is the first move, and it’s urgent given that CISA set a July 17 federal deadline.
-
Inventory every remote-access appliance you expose to the internet, not just SonicWall. VPN concentrators, secure gateways, remote desktop gateways, any box that lets people in from outside. You can’t defend what you haven’t listed. Make the list this week.
-
Check for signs you were already touched. Because the Inc group was exploiting this before the patch existed, patching alone doesn’t tell you whether they got in first. Review authentication logs on the appliance for unusual logins, new or unexpected accounts, and credential access from unfamiliar locations during the June exploitation window and after. If you don’t have those logs or can’t read them, that gap is itself something to fix.
-
Rotate credentials that touched the appliance. If there’s any chance the device was accessed, the credentials that passed through it should be treated as exposed. Reset them and require re-authentication.
-
Turn on multi-factor authentication for remote access if it isn’t already. MFA doesn’t fix a firmware flaw, but it raises the cost of using stolen credentials. Harvested passwords are worth far less when a second factor stands between them and your systems.
-
Ask who’s watching these devices between disclosures. The June window is the lesson. Someone needs to be monitoring your edge appliances for unusual behavior in the days before a vendor even knows there’s a problem. If the honest answer is “no one, really,” that’s the gap that turns a zero-day into a breach.
The appliance at the edge of your network is doing useful work every day. It’s also the door an attacker checks first. Knowing whether that door is patched, watched, and locked is a decision you can make this week, not after the ransom note arrives.
centrexIT has protected businesses across California, Nevada, Arizona, Washington, and Oregon since 2002. If you’re not sure whether your remote-access appliances are patched, monitored, or even fully inventoried, that uncertainty is worth resolving before an attacker resolves it for you. Take the 2-Minute Cybersecurity Assessment: https://centrexit.com/cyber-security-readiness-assessment/
Sources
- SonicWall disclosed two actively exploited zero-days in SMA 1000 appliances (CVE-2026-15409, CVSS 10.0, and CVE-2026-15410) on July 14, with Inc ransomware exploitation dating to at least June 22, and CISA setting a July 17 KEV remediation deadline: BleepingComputer, “Inc Ransomware Exploits SonicWall SMA 1000 Zero-Days (CVSS 10.0), Active Attacks Began Weeks Before Patch” (2026), https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-sma1000-flaws-exploited-in-zero-day-attacks-patch-now/
The centrexIT team brings decades of combined IT expertise, helping San Diego businesses thrive with secure, reliable technology solutions.
Meet Our Team