SonicWall SMA Zero-Days Exploited to Gain Root Access

A previously unidentified threat actor, designated as UTA0533, has been exploiting zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances since June 22, 2026. This activity was uncovered during a recent incident response investigation by cybersecurity firm Volexity.

The vulnerabilities exploited are CVE-2026-15409, a server-side request forgery (SSRF) flaw with a CVSS score of 10.0, and CVE-2026-15410, a post-authentication code injection vulnerability rated at 7.2. When combined, these vulnerabilities allow attackers to execute arbitrary commands and gain control over affected devices. SonicWall has released patches to address these issues.

In one instance, the attacker deployed a setuid binary named ‘ROOTRUN’ on June 22, 2026, enabling unprivileged users to execute commands with root privileges. Additionally, a Python script called ‘KNUCKLEBALL’ was introduced, containing two embedded JAR files: ‘Suo5,’ an open-source HTTP proxy, and ‘ORANGETAIL,’ a custom Java web shell. These components were integrated into legitimate SonicWall processes, allowing remote interaction via specific internet-accessible URI paths.

To maintain persistence, the attacker modified the appliance’s startup script and altered the NGINX Unit configuration to route traffic through the malicious components. On a second compromised device, similar modifications were observed, including the creation of scripts to capture unencrypted LDAP traffic, potentially harvesting usernames and passwords.

Further analysis revealed that the attacker exploited CVE-2026-15409 by issuing requests with a specific User-Agent and bmID value, establishing unauthorized WebSocket tunnels to internal services. This access facilitated the execution of commands as the root user, leading to full system compromise.

Organizations utilizing SonicWall SMA 1000 series appliances should promptly apply the available patches and review their systems for indicators of compromise. This incident underscores the critical importance of timely vulnerability management and the need for continuous monitoring to detect and mitigate sophisticated cyber threats.