Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

A Zero-Day Campaign Targets SonicWall VPN Appliances: A Critical Security Alert



A critical security alert has been issued regarding a zero-day campaign targeting SonicWall SMA 1000 VPN appliances. The threat actor, identified as UTA0533, exploited two highly critical vulnerabilities to gain root-level access before patches became available. Organizations are advised to patch their SonicWall appliances and monitor their networks for signs of unexpected access.

  • Volexity has identified a sophisticated zero-day campaign targeting SonicWall SMA 1000 VPN appliances.
  • The threat actor, UTA0533, exploited two highly critical vulnerabilities to gain root-level access before patches became available.
  • Two critical vulnerabilities were discovered: CVE-2026-15409 (SSRF) and CVE-2026-15410 (post-authentication code injection flaw).
  • The attackers gained administrative SSH access, collected sensitive data, and used it to discover additional evidence of their activity.
  • Organizations should patch their SonicWall appliances immediately and monitor networks for signs of unexpected access.
  • The use of VPN appliances as a gateway to the network is particularly high-risk and requires proper security measures.



  • Volexity, a prominent cybersecurity firm, has recently uncovered a sophisticated zero-day campaign targeting SonicWall SMA 1000 VPN appliances. The threat actor, identified as UTA0533, exploited two highly critical vulnerabilities in the SonicWall appliances to gain root-level access before patches became available.

    The first vulnerability, CVE-2026-15409, is a Server-side request forgery (SSRF) issue that allows a remote unauthenticated attacker to potentially cause the appliance to make requests to an unintended location. The second vulnerability, CVE-2026-15410, is a post-authentication code injection flaw in the Appliance Management Console (AMC) that enables a remote authenticated attacker to execute arbitrary operating system commands as administrator under certain conditions.

    Volexity's analysis revealed that the attackers used both vulnerabilities in a chain of events to compromise the SonicWall appliances. The threat actor, UTA0533, gained administrative SSH access and collected RAM, selected files, and full disk images from the compromised devices. This information was used to discover additional evidence of the attackers' activity.

    The customization of the malware for SonicWall's specific environment suggests that the threat actor was prepared specifically for this target before the campaign started. The attackers were able to read and write files as the CouchDB user, which is a serious breach of security.

    SonicWall has released patches for both vulnerabilities, but virtual appliances are not affected by the hardware UUID-derived password issue because product_uuid values only exist on physical hardware. However, they are still vulnerable to the core exploitation chain involving CVE-2026-15409 and CVE-2026-15410.

    This critical security alert highlights the importance of keeping all devices and systems up-to-date with the latest security patches. Organizations should take immediate action to patch their SonicWall appliances and monitor their networks for signs of unexpected access. The use of VPN appliances as a gateway to the network is particularly high-risk, and organizations should ensure that these devices are properly secured.

    The discovery of this zero-day campaign highlights the ongoing threat landscape and the need for continuous monitoring and incident response. Cybersecurity firms like Volexity play a critical role in identifying and reporting on these threats, helping organizations stay ahead of emerging attacks.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/A-Zero-Day-Campaign-Targets-SonicWall-VPN-Appliances-A-Critical-Security-Alert-ehn.shtml

  • https://securityaffairs.com/195626/uncategorized/volexity-uncovers-zero-day-campaign-targeting-sonicwall-vpn-appliances.html

  • https://nvd.nist.gov/vuln/detail/CVE-2026-15409

  • https://www.cvedetails.com/cve/CVE-2026-15409/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-15410

  • https://www.cvedetails.com/cve/CVE-2026-15410/


  • Published: Mon Jul 20 02:59:39 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us