Exploitation of Unpatched SonicWall SMA Zero-Day Vulnerabilities for Root Access
A threat actor exploited two zero-day vulnerabilities in SonicWall SMA 1000 series VPN appliances before public disclosure, achieving root access through chained exploits and malicious payload deployment. The attack leveraged CVE-2026-15409 and CVE-2026-15410 to bypass authentication, execute arbitrary commands, and establish persistence via compromised services and file injections.
A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026.
Cybersecurity company Volexity is tracking the activity under the moniker UTA0533. The discovery was made following an incident response investigation earlier this
*** END OF TRANSMISSION ***