CVE Tools

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

The Hacker NewsBy The Hacker News

Reported exploitedSecure Mobile Access (SMA) 1000 seriesUTA0533

Our summary

A new threat actor, tracked as UTA0533, has been actively exploiting two undisclosed vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series devices since June 22, 2026. These zero-days—CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 (CVSS 7.2)—were used to gain root access and deploy custom malware on compromised appliances. Researchers from Volexity discovered the attacks during an incident response investigation and confirmed that the vulnerabilities were chained together to allow arbitrary command execution. SonicWall has since released patches for both issues. Attackers leveraged these flaws to install persistent backdoors, steal credentials, and maintain long-term access to vulnerable systems.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store