VYPR
kevPublished Jul 14, 2026· Updated Jul 23, 2026· 17 sources

SonicWall SMA Appliances Under Zero-Day Attack Exploiting Critical Flaws

SonicWall is urging customers to patch its Secure Mobile Access (SMA) 1000 Series appliances following active exploitation of two zero-day vulnerabilities, CVE-2026-15409 and CVE-2026-15410.

SonicWall has issued an urgent call to action for its customers, advising them to upgrade firmware on Secure Mobile Access (SMA) 1000 Series appliances due to active exploitation of two critical zero-day vulnerabilities. The flaws, identified as CVE-2026-15409 and CVE-2026-15410, are being exploited in tandem by attackers to compromise these secure remote access gateways.

CVE-2026-15409 is a critical Server-Side Request Forgery (SSRF) vulnerability within the SMA1000 Appliance Work Place interface. This flaw could permit unauthenticated remote attackers to compel the appliance to initiate requests to unintended external locations, potentially exposing internal network resources. The second vulnerability, CVE-2026-15410, is a high-severity code injection flaw affecting the SMA1000 Appliance Management Console. Exploitation of this bug by an authenticated administrator could lead to arbitrary OS command execution and subsequent remote code execution on the affected appliance.

These vulnerabilities impact specific models within the SonicWall SMA 1000 series, including the SMA6210, SMA7210, and the virtual appliance SMA8200v. Affected firmware versions include 12.4.3-03245, 12.4.3-03387, 12.4.3-03434, 12.5.0-02283, 12.5.0-02624, and 12.5.0-02800. SonicWall has released hotfix firmware versions 12.4.3-03453 and 12.5.0-02835 to address these issues.

SonicWall confirmed that these vulnerabilities are being actively exploited in the wild, indicating a significant and immediate threat to organizations relying on these appliances for secure remote access. The company proactively alerted customers before the public release of the security advisory, providing access to hotfixes and offering a script to assist with resolution. A spokesperson emphasized that patching alone is insufficient and urged customers to meticulously review logs for indicators of compromise.

Beyond patching, SonicWall recommends that organizations that suspect compromise should consider re-imaging affected hardware appliances or re-deploying virtual appliances. Furthermore, all user and administrator passwords must be reset, and any configured Time-based One-Time Password (TOTP) tokens should be reset as a precautionary measure. This comprehensive approach is crucial to ensure complete remediation and prevent further unauthorized access.

SonicWall SMA appliances and firewalls are frequently targeted by threat actors, often exploiting zero-day vulnerabilities or leveraging previously disclosed flaws. The active exploitation of these new vulnerabilities underscores the persistent threat landscape and the importance of timely patching and robust security monitoring for critical network infrastructure. The company has credited Adam Babis of SonicWall PSIRT for discovering and reporting these vulnerabilities.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has officially added both CVE-2026-15409 and CVE-2026-15410 to its Known Exploited Vulnerabilities (KEV) catalog, confirming their active exploitation in the wild. This addition mandates federal agencies to patch affected SonicWall SMA1000 appliances by July 17, 2026, under Binding Operational Directive (BOD) 26-04, or discontinue use if mitigation is not possible.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has officially added both CVE-2026-15409 and CVE-2026-15410 to its Known Exploited Vulnerabilities (KEV) catalog. This inclusion mandates that federal agencies must patch these vulnerabilities by July 17th to mitigate the risk of compromise, underscoring the critical nature of these flaws.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has officially added both CVE-2026-15409 and CVE-2026-15410 to its Known Exploited Vulnerabilities (KEV) catalog. This addition mandates that Federal Civilian Executive Branch (FCEB) agencies must apply the necessary patches by July 17, 2026, to mitigate the risks associated with these actively exploited zero-day flaws in SonicWall SMA 1000 series appliances.

The new article provides additional details on the exploitation of SonicWall SMA1000 Series appliances, specifically naming CVE-2026-15409 (SSRF, CVSS 10.0) and CVE-2026-15410 (post-auth code injection, CVSS 7.2). It also outlines specific indicators of compromise within log files such as suspicious requests to /api/login or /api/logout, and unusual entries in ctrl-service.log, recommending re-imaging or redeployment if exploitation is detected.

Rapid7's Managed Detection and Response (MDR) team has provided further details on the active exploitation of these SonicWall SMA1000 zero-days, including a technical breakdown of the two-stage attack chain. They observed attackers leveraging CVE-2026-15409 (SSRF) to establish a tunnel to internal services, then exploiting CVE-2026-15410 (code injection via path traversal in the remove_hotfix workflow) to achieve root-level command execution and trigger a system reboot. A Python proof-of-concept for the initial SSRF vulnerability has been released, and a Metasploit module for the combined exploit chain is reportedly in development.

The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-15409 and CVE-2026-15410 to its Known Exploited Vulnerabilities (KEV) Catalog. This inclusion mandates remediation by July 17, highlighting the critical nature of these zero-day vulnerabilities affecting SonicWall SMA 1000 Series appliances and the urgent need for patching.

The Cybersecurity and Infrastructure Security Agency (CISA) has officially added both CVE-2026-15409 and CVE-2026-15410 to its Known Exploited Vulnerabilities (KEV) catalog, underscoring the severity and active exploitation of these SonicWall SMA1000 zero-days. Rapid7 researchers have also confirmed that exploitation of these vulnerabilities began as early as June 22, indicating a significant period of in-the-wild activity before public disclosure.

The new article confirms that exploitation of the SonicWall SMA1000 zero-day vulnerabilities, CVE-2026-15409 and CVE-2026-15410, is actively occurring in the wild. It details the exploit chain, starting with a server-side request forgery (SSRF) flaw in the /wsproxy feature that leads to unauthenticated remote code execution, followed by a path traversal vulnerability used to escalate privileges to root. Compromised devices are being used for credential harvesting and pivoting into Active Directory environments, and CISA has added these vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog.

The Inc ransomware group has been actively exploiting these SonicWall SMA zero-days, chaining CVE-2026-15409 and CVE-2026-15410 to achieve root-level access. Rapid7 telemetry indicates that attackers are using the compromised appliances as an initial access vector to steal credentials, establish persistence, and move laterally within victim networks, with at least one instance resulting in successful ransomware deployment.

This Volexity report provides deeper technical analysis of the exploitation chain, detailing the specific zero-day vulnerabilities CVE-2026-15409 (SSRF) and CVE-2026-15410 (Command Injection) used by the threat actor UTA0533. It further reveals the custom malware deployed and outlines the earliest observed compromise date of June 22, 2026, significantly predating the public disclosure.

This new report from The Hacker News attributes the exploitation to a previously undocumented threat actor, UTA0533, and provides a detailed timeline of their activities beginning as early as June 22, 2026. It further elaborates on the specific malware and tradecraft employed, including the use of custom ELF executables and Java web shells like KNUCKLEBALL and ORANGETAIL, and details how the attackers established persistence by modifying startup scripts and NGINX configurations.

The new reporting from Volexity attributes the exploitation of these SonicWall zero-days to a threat actor tracked as UTA0533, with exploitation believed to have begun as early as June 22. While the actor's motivation remains unclear, the sophisticated nature of the attack, including the deployment of custom malware like KnuckleBall and its associated tools, suggests potential state-sponsored APT activity rather than typical cybercrime operations. CISA has since added CVE-2026-15409 and CVE-2026-15410 to its Known Exploited Vulnerabilities (KEV) catalog.

New details from incident response firm Volexity reveal that a previously unknown threat actor, tracked as UTA0533, began exploiting these SonicWall SMA1000 vulnerabilities as early as June 22, weeks before SonicWall's public disclosure. The exploitation chain involved using CVE-2026-15409 for unauthenticated WebSocket tunnels to internal services, querying CouchDB for a 'product_uuid', and then leveraging CVE-2026-15410 to execute commands as root, ultimately deploying custom Java-based malware families named Sou5 and ORANGETAIL.

This new reporting from Volexity researchers indicates that the exploitation of SonicWall SMA 1000 series zero-days, CVE-2026-15409 and CVE-2026-15410, began as early as June 22, 2026, weeks before the vulnerabilities were publicly disclosed. The attackers successfully installed custom malware, including proxy tools and a web shell, to maintain persistent access, steal credentials, and capture network traffic, though their ability to move laterally within victim networks was reportedly limited.

The newly disclosed attack chain involves threat actor UTA0533 chaining CVE-2026-15409 and CVE-2026-15410 to deploy custom malware, specifically ROOTRUN and KNUCKLEBALL, for persistence and lateral movement. Post-compromise activity included using tcpdump to capture unencrypted LDAP traffic in an attempt to pivot to internal systems. SonicWall has since released hotfixes for affected SMA 1000 series models.

The July InfraTrust report further details the exploitation of SonicWall SMA1000 devices, noting that attackers not only gained remote code execution but also stole valuable credentials, active session databases, and time-based one-time password seed configurations. Beyond simply patching, organizations must now conduct forensic reviews, rebuild compromised appliances, rotate all affected credentials, and reseed MFA tokens to mitigate the full impact of the breach.

Synthesized by Vypr AI