Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appliances
Unknown hackers exploited two SonicWall SMA 1000 zero-days to gain root access on VPN appliances before patches became available. Volexity published its findings after conducting an incident response investigation involving a compromised organization whose SonicWall SMA 1000 series VPN appliances were hit with zero-day exploits starting June 22, 2026. The threat actor, which Volexity tracks […]

Volexity published its findings after conducting an incident response investigation involving a compromised organization whose SonicWall SMA 1000 series VPN appliances were hit with zero-day exploits starting June 22, 2026. The threat actor, which Volexity tracks as UTA0533, chained two vulnerabilities, respectively tracked as CVE-2026-15409 (CVSS score of 10.0) and CVE-2026-15410 (CVSS score of 7.2) to achieve root-level access on the devices before patches existed.
SonicWall patched both vulnerabilities this week and confirmed the active exploitation of the two zero-day vulnerabilities. The vulnerabilities were internally discovered and reported by Adam Babis of the company’s PSIRT.
Related breach coverage
- SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch2026-07-20
The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533. The post SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch appeared first on SecurityWeek.
- SonicWall warns of active exploitation of two SMA 1000 zero-days2026-07-15
SonicWall warns of active attacks exploiting two SMA 1000 zero-days, including a flaw enabling arbitrary command execution. SonicWall confirmed the active exploitation of two zero-day vulnerabilities affecting Secure Mobile Access (SMA) 1000 appliances. The vulnerabilities were internally discovered and reported by Adam Babis of the company’s PSIRT. The company investigated multiple incidents indicating these vulnerabilities […]
- Attacker Used AI to Build Custom PowerShell Recon Malware2026-07-14
Huntress found an AI-generated PowerShell script used for AD reconnaissance, showing attackers are using AI to create custom, evasive tools. During an incident response investigation on June 3, 2026, Huntress analyst Jevon Ang recovered a PowerShell script from a compromised Windows Server that the attacker had used to map out the victim’s Active Directory environment. […]
- SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits2026-07-15
SonicWall SMA1000 zero-day vulnerabilities CVE-2026-15409 and CVE-2026-15410 can be exploited for remote code execution. The post SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits appeared first on SecurityWeek.
