Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Hackers Hijack Government Websites to Deliver Malware via Trusted Links
July 21, 2026
New Crypter Evades EDR and Deletes Malware From Disk
July 21, 2026
Google Gemini 3.5 Flash AI Speeds Vulnerability Detection and Patching
July 21, 2026
Home/CyberSecurity News/Critical SonicWall VPN Vulnerabilities Exploited in the Wild
CyberSecurity News

Critical SonicWall VPN Vulnerabilities Exploited in the Wild

Key Takeaways Two critical zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) VPN appliances are being actively exploited in the wild. The vulnerabilities, CVE-2026-15409 (SSRF) and...

Marcus Rodriguez
Marcus Rodriguez
July 21, 2026 3 Min Read
4 0

Key Takeaways

  • Two critical zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) VPN appliances are being actively exploited in the wild.
  • The vulnerabilities, CVE-2026-15409 (SSRF) and CVE-2026-15410 (command injection), allow unauthenticated attackers to gain root access and deploy custom malware.
  • Affected devices include SMA 1000 series models (6210, 7210, and 8200v).
  • SonicWall has released hotfixes (12.4.3-03453 and 12.5.0-02835) to address these flaws.

Active Exploitation of SonicWall Zero-Days Leads to Root Compromise

Cybersecurity researchers have uncovered active exploitation of two zero-day vulnerabilities within SonicWall Secure Mobile Access (SMA) VPN appliances. These critical flaws are being chained by attackers to achieve root access on compromised devices and deploy sophisticated custom malware.

Table Of Content

  • Key Takeaways
  • Active Exploitation of SonicWall Zero-Days Leads to Root Compromise
  • SonicWall 0-day Vulnerabilities Exploited
  • Malware Deployment and Post-Compromise Activity
  • What You Should Do

The investigation, initiated in early July 2026 by cybersecurity firm Volexity, focused on an intrusion involving SonicWall SMA VPN hardware. The firm’s forensic analysis revealed that a threat actor, identified as UTA0533, leveraged a series of previously unknown vulnerabilities. This sophisticated attack allowed the group to compromise the appliances, install bespoke malware, intercept network traffic, and attempt to move laterally within victim networks.

SonicWall 0-day Vulnerabilities Exploited

Volexity found evidence that exploitation of these vulnerabilities began as early as June 22, 2026. SonicWall officially disclosed the issues on July 14, 2026, confirming that SMA 1000 series models, specifically 6210, 7210, and 8200v, were impacted. The vendor promptly released hotfixes 12.4.3-03453 and 12.5.0-02835 to mitigate the risks.

The attack chain involved two distinct vulnerabilities. The first, CVE-2026-15409, is a Server-Side Request Forgery (SSRF) flaw. This vulnerability enabled unauthenticated attackers to exploit the /wsproxy endpoint to establish WebSocket tunnels to internal localhost services. The second, CVE-2026-15410, is a command injection vulnerability, which attackers leveraged to achieve arbitrary code execution on the appliances.

By exploiting CVE-2026-15409, attackers gained unauthorized access to internal services, including CouchDB on port 1050 and the SMA control service on port 8188. This access was then utilized to upload files and gather crucial information necessary for invoking privileged functions.

CVE-2026-15410 facilitated a path traversal vulnerability within the execRemoveHotfix function. This allowed attackers to execute a file placed in the /tmp directory with root privileges. Indicators of this exploitation include log entries referencing “remove_hotfix” and paths such as “../../../../../tmp/1234.sh”.

Malware Deployment and Post-Compromise Activity

On at least one compromised appliance, the threat actor UTA0533 installed a setuid root execution tool named “xzfind,” internally referred to as ROOTRUN. The group also deployed a Python-based implant known as KNUCKLEBALL, saved as deploy_new.py.

This sophisticated malware injected Java payloads into a legitimate SonicWall process and established persistence by modifying a startup script. The injected payloads included Suo5, an HTTP proxy-forwarding tool, and ORANGETAIL, a custom Java webshell that bears resemblance to the Behinder malware family.

To further evade detection and maintain access, the attackers modified the NGINX Unit configuration. This alteration redirected requests from /api/login and /api/logout to their hidden implants. These backdoors were designed to activate only when an unusual and invalid browser user-agent string was presented, making them harder to discover through routine monitoring.

Volexity also documented significant post-compromise activity, including the use of tcpdump to capture unencrypted LDAP traffic. This suggests the attackers were actively attempting to harvest usernames and passwords, signaling an intent to pivot from the compromised VPN appliances into the internal network infrastructure.

What You Should Do

  • Immediately apply SonicWall hotfixes 12.4.3-03453 and 12.5.0-02835 to all affected SMA 1000 series models.
  • Review /var/log/aventail/ logs for any suspicious activity related to /wsproxy.
  • Inspect /tmp and /var/tmp directories for any unexpected or unauthorized files.
  • Check /var/lib/unit/conf.json for any unauthorized routes pointing to 127.0.0.1:8085.
  • Deploy Volexity’s published YARA rules to detect ROOTRUN, KNUCKLEBALL, and associated malware payloads within your network.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVECybersecurityExploitMalwareSecurityThreatVulnerabilityzero-day

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Linux Kernel Patches Over 400 Vulnerabilities

Next Post

Critical Microsoft Defender XDR Flaw Hides Public Connections

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical GitHub Actions Flaw Backdoors AsyncAPI npm Packages with Miasma RAT
July 21, 2026
Critical SharePoint RCE Vulnerability CVE-2023-29357 Actively Exploited
July 21, 2026
Top 10 Malware Used by Threat Actors in Recent Cyberattacks
July 21, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us