AUTO-UPDATED

Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appliances

SonicWall has released patches for two zero-day vulnerabilities, CVE-2026-15409 and CVE-2026-15410, which threat actor UTA0533 used to gain root-level access to SMA 1000 series VPN appliances since June 2026.

Key Points

  • Threat actor UTA0533 chained a CVSS 10.0 SSRF vulnerability and a CVSS 7.2 code injection flaw to compromise physical and virtual VPN appliances.
  • The exploit chain allowed attackers to bypass authentication, execute arbitrary OS commands as administrator, and install custom malware like the ORANGETAIL web shell.
  • Attackers captured cleartext LDAP credentials by deploying scripts to monitor network traffic directly from the compromised VPN hardware.
  • SonicWall confirmed active exploitation in the wild and issued security patches to address the vulnerabilities discovered by their internal PSIRT team.
  • A separate authentication bypass exists for physical appliances due to a world-readable hardware UUID file, though it was not used in this specific campaign.

Why it Matters

VPN appliances serve as critical gateways for network authentication, making them high-value targets for attackers seeking to intercept credentials and gain persistent access to internal systems. Organizations must prioritize patching these vulnerabilities immediately to prevent unauthorized administrative control and potential data exfiltration from their secure environments.
Securityaffairs.com Published by Pierluigi Paganini
Read original