SonicWall has released patches for two zero-day vulnerabilities, CVE-2026-15409 and CVE-2026-15410, which threat actor UTA0533 used to gain root-level access to SMA 1000 series VPN appliances since June 2026.
Key Points
- Threat actor UTA0533 chained a CVSS 10.0 SSRF vulnerability and a CVSS 7.2 code injection flaw to compromise physical and virtual VPN appliances.
- The exploit chain allowed attackers to bypass authentication, execute arbitrary OS commands as administrator, and install custom malware like the ORANGETAIL web shell.
- Attackers captured cleartext LDAP credentials by deploying scripts to monitor network traffic directly from the compromised VPN hardware.
- SonicWall confirmed active exploitation in the wild and issued security patches to address the vulnerabilities discovered by their internal PSIRT team.
- A separate authentication bypass exists for physical appliances due to a world-readable hardware UUID file, though it was not used in this specific campaign.