← Back to Feed

INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

CVE-2021-20038CVE-2021-20045

August 3, 2026 · The Hacker News · Severity: CRITICAL

The INC ransomware group has emerged as a dominant threat actor exploiting vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series appliances. The attackers are leveraging known flaws, including CVE-2021-20038 and CVE-2021-20045, to gain initial access and deploy ransomware on targeted networks. These vulnerabilities, which SonicWall patched in 2021, allow remote code execution and authentication bypass, enabling the group to compromise unpatched systems. Organizations using unpatched SonicWall SMA 1000 devices are at risk, particularly in sectors like healthcare, finance, and government. The INC ransomware group has been actively targeting these systems to encrypt data and demand ransom payments. This campaign highlights the ongoing risk posed by delayed patching of known vulnerabilities, as threat actors continue to exploit outdated systems for financial gain. SonicWall users are urged to apply the latest security updates immediately to mitigate these risks.

INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws