SonicWall, Rapid7, and Volexity establish a July CVE-2026-15409/CVE-2026-15410 exploitation chain that can produce root appliance compromise. Source-qualified reporting separately associates continued weaponization with INC Ransom, while Volexity tracks its observed activity as UTA0533. Hunt.io adds a separate unattributed post-disclosure CVE-2026-15409 cluster reconstructed from attacker infrastructure: 250 exploitable target identifiers, LDAP configuration recovered from 168 targets, SAM/LSA theft in at least nine Active Directory domains, and full DCSync in five. Hunt.io does not establish CVE-2026-15410 use, ransomware, INC, UTA0533, or country attribution.
The retained record scopes this as zero-day edge-appliance exploitation / ransomware initial access activity during Volexity observed a separate cluster beginning 2026-06-22. Hunt.io retained post-disclosure scanning on 2026-07-16 and active exploitation on 2026-07-17. Hunt.io published its reconstruction on 2026-09-10; publication is not a first-seen date.. Compromised SMA1000 appliances can become internal attack platforms. Existing reporting establishes session, credential, TOTP, malware, and lateral-movement risk; Hunt.io additionally documents LDAP bind-password recovery, appliance-hosted secretsdump, SAM/LSA theft, domain-controller machine-account hash reuse, pass-the-hash, and DRSUAPI replication. Confirmed DCSync can require domain-wide identity recovery, not only appliance rebuild.[1][2][3][4][5][6][7][8][9][10][11][12][13][14][15][16][17][18][19][20][21]
Upgrade 6210/7210/8200v to 12.4.3-03526 or later or 12.5.0-02952 or later; no workaround exists. Preserve evidence and assess every internet-facing pre-fix appliance. Hunt historical July telemetry for 95.181.173[.]36, http://95.181.173[.]36:80/secretsdump, SHA-256 690f5031deede7d3357d0ca24c89866ae8c60e6c63b3a2c8bba813a6ac10ae5b, /tmp/secretsdump, policy_file.xml access, appliance-origin SMB/pass-the-hash/DRSUAPI, and staged NTDS-related output. Treat the IP and URL as historical shared-infrastructure pivots. If SAM/LSA theft, machine-account exposure, or DCSync is confirmed, expand recovery to Active Directory trust. Keep the Hunt.io cluster separate from INC Ransom, UTA0533, and the September CVEs.[1][2][3][4][5][6][7][8][9][10][11][12][13][14][15][16][17][18][19][20][21]
Confirmed reporting is separated from attribution, victim, and prevalence claims that the retained sources do not establish. Confidence: High for official exploitation, the established July two-CVE chain, current fixes, KEV state, and Hunt.io retained-directory artifacts and outcomes; moderate for the source-qualified INC association and Hunt.io council linkage; no attribution confidence for the Hunt.io cluster..[1][2][3][4][5][6][7][8][9][10][11][12][13][14][15][16][17][18][19][20][21]