Multiple threat actors are actively exploiting two critical zero-day vulnerabilities (CVE-2026-15409 and CVE-2026-15410) affecting SonicWall Secure Mobile Access (SMA) 1000 Series VPN appliances to gain unauthorized root-level access. Observed attacks leveraged a chained exploitation path to bypass authentication, execute arbitrary commands, deploy custom malware, establish persistent access, and capture sensitive credentials and network traffic. The campaign, attributed by Volexity to the threat actor UTA0533, began prior to the public disclosure of the vulnerabilities, highlighting a high level of sophistication and the immediate risk to internet-facing SMA appliances. Organizations using affected devices should apply the latest security patches without delay, investigate for indicators of compromise, rotate potentially exposed credentials, and closely monitor systems for signs of unauthorized activity.
The observed attacks targeted SonicWall Secure Mobile Access (SMA) 1000 Series VPN appliances by chaining two zero-day vulnerabilities, CVE-2026-15409 and CVE-2026-15410, to achieve unauthenticated remote code execution and full root-level compromise. The attack began with the exploitation of a pre-authentication /wsproxy bypass (CVE-2026-15409), which allowed attackers to establish a WebSocket tunnel to services restricted to localhost. Through this tunnel, the threat actor accessed internal services, including CouchDB and the SMA control service, enabling file read/write operations and the execution of malicious commands. The second vulnerability, a path traversal flaw in the remove_hotfix workflow of the SMA control service (CVE-2026-15410), was then exploited to escalate privileges from an unprivileged service account to the root user, granting complete control of the appliance.
Following successful exploitation, the threat actor deployed multiple custom payloads to establish persistence and facilitate post-exploitation activities. These included the ROOTRUN setuid binary for privileged command execution, the KNUCKLEBALL Python loader, the ORANGETAIL Java web shell, and the Suo5 HTTP proxy to enable covert remote access. Persistence was achieved by modifying legitimate startup scripts and altering the NGINX Unit configuration to expose attacker-controlled endpoints. Additional tools were used to capture unencrypted LDAP traffic and harvest credentials, while temporary files stored in the /tmp and /var/tmp directories supported privilege escalation and malware staging. With root-level access, the attackers were able to intercept authentication data, access cached credentials, manipulate appliance configurations, and maintain long-term unauthorized access to the compromised VPN infrastructure. The full exploitation chain is detailed below.
Exploitation Demonstration:
Ease of Exploitation:
Since the attack chain begins with a pre-authentication vulnerability that does not require legitimate user credentials, remote attackers can immediately target internet-facing SonicWall SMA 1000 Series appliances, making the ease of exploitation high. By chaining CVE-2026-15409 and CVE-2026-15410, attackers can bypass authentication, gain access to internal localhost services, escalate privileges to the root user, and perform arbitrary actions with minimal user interaction. The public availability of proof-of-concept (PoC) code further lowers the barrier to exploitation, increasing the likelihood of widespread attacks against unpatched systems. Organizations with exposed SMA appliances that have not applied the latest security patches face a significant risk of compromise.
Conclusion:
Successful exploitation of these vulnerabilities can result in the complete compromise of affected SonicWall SMA 1000 Series appliances, allowing attackers to gain root-level privileges and execute arbitrary commands. This level of access enables the deployment of persistent malware, the theft of cached or transmitted credentials, interception of network traffic, modification of system configurations, and unauthorized access to sensitive enterprise resources. As VPN appliances often serve as gateways to internal networks, a compromised device can facilitate further intrusion, privilege escalation, and lateral movement, increasing the risk of data breaches, operational disruption, and long-term unauthorized access.
Successful exploitation of these vulnerabilities can result in the complete compromise of affected SonicWall SMA 1000 Series appliances, allowing attackers to gain root-level privileges and execute arbitrary commands. This level of access enables the deployment of persistent malware, the theft of cached or transmitted credentials, interception of network traffic, modification of system configurations, and unauthorized access to sensitive enterprise resources. As VPN appliances often serve as gateways to internal networks, a compromised device can facilitate further intrusion, privilege escalation, and lateral movement, increasing the risk of data breaches, operational disruption, and long-term unauthorized access.