securityaffairs.com 7/20/2026, 7:40:49 AM · external

Zero day exploits hit SonicWall VPN, giving attackers root access

Zero day exploits hit SonicWall VPN, giving attackers root access
CyberSIXT Evidence Panel
CISA KEV Listed in KEV
Patch Patch Available
Threat Actor
UTA0533

VOLEXITY has uncovered a significant zero-day exploitation campaign targeting SonicWall SMA 1000 VPN appliances, where unidentified hackers utilized two vulnerabilities (CVE-2026-15409 and CVE-2026-15410) to gain root access. The first vulnerability (CVSS 10.0) is a server-side request forgery (SSRF) allowing attackers to make unauthorized requests, while the second (CVSS 7.2) is a post-authentication code injection flaw permitting attackers to execute arbitrary commands as an administrator.

SonicWall has since issued patches after confirming these vulnerabilities' active exploitation. The campaign, attributed to threat actor UTA0533, commenced on June 22, 2026, and involved sophisticated methods including customized malware and memory exploitation to maintain access and intercept network traffic. Volexity's findings highlight the critical need for vigilance in monitoring and securing VPN appliances to protect against such breaches.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline