< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

4 clusters · 9 sources · 26 days · First seen · Last updated

SonicWall SMA1000 vulnerability exploitation

Overview

In mid‑July 2026, SonicWall warned that two critical flaws in its SMA1000 series VPN appliances – CVE‑2026‑15409 (a pre‑authentication SSRF with a CVSS score of 10.0) and CVE‑2026‑15410 (a post‑authentication code‑injection) – were being actively exploited in the wild. The company released hot‑fixes, supplied indicators of compromise, and advised customers to re‑image or redeploy devices, reset credentials, and conduct forensic checks. The U.S. CISA added the flaws to its Known Exploited Vulnerabilities Catalog.

Two days later, further detail emerged that a threat actor, identified as UTA0533, had chained the two zero‑day flaws to install custom malware, gain root access, modify startup scripts, and harvest LDAP credentials before the vulnerabilities were publicly disclosed on 22 June 2026. SonicWall confirmed that patches for both CVEs had been issued during the same week.

A follow‑up report on 19 July 2026 described additional activity against the SMA1000 series. Attackers deployed a Python‑based implant dubbed KNUCKLEBALL and a setuid tool named ROOTRUN, both used to maintain persistence and capture unencrypted traffic after exploiting the SSRF and command‑injection bugs. The same report also noted a separate supply‑chain compromise of the Russian ViPNet secure‑communication suite, but the SonicWall exploitation remained the primary focus of the ongoing incident response.

By August 2026, reports indicated that ransomware gangs had also begun exploiting these vulnerabilities. Researchers identified additional custom malware, including Sou5 and ORANGETAIL, being deployed. Shadowserver reported that over 380 SMA1000 appliances remained exposed online.

Entities

Volexity · Shadowserver · CISA · Apache Tomcat · SonicWall

Timeline

  1. 7 days ago

    [TECHNOLOGY] 3 sources
    SonicWall SMA1000 vulnerabilities exploited by ransomware gangs

    Ransomware gangs are exploiting SonicWall SMA1000 vulnerabilities, prompting CISA to order federal agencies to patch. Separate exploits have also been identified in Apache Tomcat.

  2. 28 days ago

    [TECHNOLOGY] 2 sources
    Cyber Attacks Compromise ViPNet Communications and SonicWall VPN

    Two cyber incidents: a supply‑chain attack on ViPNet software compromised Russian government communications, and zero‑day exploits in SonicWall VPN devices allowed attackers to install custom malware and gain ​

  3. about 1 month ago

    [TECHNOLOGY] 2 sources
    SonicWall SMA1000 Zero‑Day Flaws Actively Exploited Before Public Disclosure

    Critical SSRF and code‑injection bugs in SonicWall SMA1000 VPN appliances were exploited by a threat actor before disclosure; SonicWall has now released patches.

  4. about 1 month ago

    [TECHNOLOGY] 2 sources
    SonicWall SMA1000 gateways under active exploitation of critical flaws

    SonicWall warns that two critical flaws (CVE‑2026‑15409, CVE‑2026‑15410) in SMA1000 gateways are being actively exploited; patches and remediation steps have been issued.

Sources

cinemagia.wordpress.com · cybersecuritynews.com · flagthis.com · horizon3.ai · nationalcybersecurity.com · sf-encyclopedia.com · solidsoftwaretools.com · thecyberexpress.com · thehackernews.com