LIVE · cybersecurity feed
Live wire
CVE-2026-15409critical

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

A sophisticated threat actor, tracked as UTA0533, has been exploiting two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. These exploits, CVE-2026-15409 and CVE-2026-15410, were chained together to achieve arbitrary command execution and gain root access. The actor leveraged these vulnerabilities to deploy custom malware, establish persistence, and potentially exfiltrate sensitive data.

zeroday.news · 13d ago

Reports indicate that a sophisticated threat actor, identified as UTA0533, has been actively exploiting two zero-day vulnerabilities within SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. These exploits were reportedly chained together to achieve arbitrary command execution and subsequently gain root access on affected systems. The exploitation occurred prior to the public disclosure of these vulnerabilities, which are tracked as CVE-2026-15409 and CVE-2026-15410.

The technical mechanism behind this attack involved the sequential exploitation of both vulnerabilities. While the specific nature of CVE-2026-15409 and CVE-2026-15410 was not detailed, the chaining of zero-day flaws is a common tactic to bypass multiple security layers. One vulnerability might be used to achieve an initial foothold or information leak, which is then leveraged by the second to escalate privileges or execute arbitrary code. In this instance, the ultimate outcome was arbitrary command execution, a critical capability that allows an attacker to run their own code on the compromised device.

Upon gaining arbitrary command execution, the threat actor proceeded to achieve root access. Root access, or administrative privileges, provides an attacker with complete control over the operating system and its functions. This level of access is highly sought after by adversaries as it allows them to manipulate system configurations, install software, and access sensitive data without restriction.

With root access established, UTA0533 reportedly deployed custom malware. The deployment of custom malware suggests a tailored approach by the attacker, likely designed to evade standard security detections. This malware was then used to establish persistence on the compromised SMA appliances, ensuring continued access even after reboots or attempts to remediate the initial exploit. The ultimate objective of this persistent access and malware deployment was to potentially exfiltrate sensitive data, indicating a data theft or espionage motivation.

SonicWall SMA 1000 series VPN appliances are widely used by organizations to provide secure remote access to internal networks and resources. The exploitation of such devices is particularly concerning because they often serve as a gateway to an organization's critical infrastructure. Successful compromise can therefore lead to broader network intrusions.

Mitigation for this class of vulnerability typically involves applying vendor-supplied patches as soon as they become available. Given that these were zero-day exploits, organizations would have been vulnerable until patches were released. Beyond patching, best practices include implementing robust network segmentation, monitoring VPN appliance logs for anomalous activity, and deploying endpoint detection and response (EDR) solutions on systems accessible via VPN to detect post-exploitation activities. Regularly reviewing and hardening VPN configurations, along with strong authentication mechanisms, also helps reduce the attack surface.

This incident underscores the persistent threat posed by sophisticated actors targeting critical network infrastructure components with previously unknown vulnerabilities. The use of chained zero-days to achieve root access and establish persistence highlights the advanced capabilities of groups like UTA0533 and the continuous need for organizations to maintain a proactive and multi-layered security posture, focusing on rapid patching, continuous monitoring, and incident response capabilities.

sonicwallvpnzero-dayexploitationmalware
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

security

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

security

BGP ORIGIN attribute manipulation and its impact on the Internet

By doing in-depth testing, we found nearly 70% of BGP paths experience ORIGIN attribute rewrites by transit providers seeking traffic advantages. We examine the global impact of this practice and argue for deprecating ORIGIN in route selection.

security

Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry

The new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government.

security

'Wrench' attacks against crypto holders appear to be on the rise

There are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say.

vulnerability

Microsoft blames massive Microsoft 365 outage on maintenance bug

Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. [...]