defense · TheHackerNews
SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances were exploited as zero-days beginning June 22, 2026, according to Volexity's investigation of a compromise. The threat actor, tracked as UTA0533, leveraged CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 (CVSS 7.2) to gain root access on two affected devices. The attacker deployed multiple custom tools including ROOTRUN (a setuid binary), KNUCKLEBALL (a Python script), ORANGETAIL (a Java web shell), and Suo5 (an HTTP proxy) to establish persistence and maintain access via injected JAR archives. Additional exploitation involved reading unencrypted LDAP credentials and leveraging CouchDB to bypass authentication mechanisms. SonicWall released patches this week.
Organizations operating SonicWall SMA appliances—particularly defense contractors managing sensitive networks and healthcare providers relying on remote access—should prioritize patching both CVE-2026-15409 and CVE-2026-15410 immediately. For CMMC-certified defense contractors and SOC2-scoped SaaS platforms, VPN appliance security is a critical control point; unpatched remote access gateways create direct paths to CUI and customer data. The exploitation chain—leveraging pre-authentication bypasses, privilege escalation, and persistent backdoors—demonstrates sophisticated adversary capabilities that bypass typical perimeter controls. An Omniware engagement can scope asset inventory, patch management workflows, and post-incident forensics for affected appliances.
Source: The Hacker News - https://thehackernews.com/2026/07/sonicwall-sma-zero-days-exploited.html
Source: TheHackerNews
All briefings