general · BleepingComputer
SonicWall SMA1000 Secure Mobile Access appliances have been exploited in zero-day attacks since at least June 22, 2026, according to incident response firm Volexity. Two vulnerabilities—CVE-2026-15409 (a critical server-side request forgery flaw) and CVE-2026-15410 (a high-severity command injection vulnerability)—affect SMA1000 models 6210, 7210, and 8200v. Attackers exploited these flaws in a multi-stage chain to gain root access and install custom malware, including a dropper called KNUCKLEBALL and two Java-based families, Sou5 (functioning as a reverse proxy) and ORANGETAIL (a webshell). SonicWall released patches in versions 12.4.3-03453 and 12.5.0-02835.
For defense contractors and other organizations relying on SonicWall SMA1000 appliances for secure remote access, this exploitation chain presents material risk to CUI and regulated data. Contractors subject to CMMC Level 2 and 3 requirements should prioritize patching immediately, as unpatched VPN appliances fail to meet access control and audit logging mandates. Similarly, healthcare providers (HIPAA) and SaaS platforms (SOC 2) using SMA1000 devices must treat this as urgent, since successful compromise can lead to lateral movement into protected networks and facilitate data exfiltration. An Omniware engagement can scope the exposure in your environment, validate patch deployment, and assess whether the compromise indicators Volexity identified are present in your logs.
Source: BleepingComputer - https://www.bleepingcomputer.com/news/security/sonicwall-sma1000-flaws-exploited-as-zero-days-to-push-custom-malware/Source: BleepingComputerAll briefings
Source: BleepingComputer
All briefings