- Two zero-day vulnerabilities, CVE-2026-15409 and CVE-2026-15410, in SonicWall SMA1000 appliances were actively exploited by threat actor UTA0533 for weeks before patches were released.
- Exploitation allowed the installation of custom malware on vulnerable VPN appliances.
- The SMA1000 series provides secure access to corporate resources, making these flaws highly impactful.
The threat actor UTA0533 leveraged these zero-days in a chained manner to achieve initial access and persistence on target networks. Specific details on the exploitation chain are not fully disclosed but likely involve remote code execution to deploy custom malware payloads. These VPN appliances are often perimeter devices, providing a direct route into internal networks bypassing traditional endpoint defenses.
These vulnerabilities are critical for network infrastructure penetration tests. Identify SonicWall SMA1000 appliances within the scoped environment, prioritize version identification, and check for the applicable security patches. While direct zero-day exploitation is not possible post-patch, understanding the attack surface and potential for similar flaws in other unpatched network devices is valuable. Focus on configuration reviews for remote access solutions.
Organizations must immediately apply the latest patches released by SonicWall for SMA1000 series appliances. Conduct thorough forensic investigations to detect any signs of compromise if patches were not applied promptly.