Cybersecurity researchers have uncovered a threat actor exploiting zero-day vulnerabilities in SonicWall Secure Mobile Access 1000 series appliances. The group, identified as UTA0533 by cybersecurity firm Volexity, was able to compromise these devices before the vulnerabilities were publicly disclosed on June 22, 2026. The vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, allowed attackers to execute arbitrary commands and control the affected devices. SonicWall has since released patches to address these critical issues.
Volexity's investigation revealed that the threat actor used sophisticated techniques, including multiple zero-day exploits and malware specifically crafted for SonicWall SMA VPN appliances. The attackers targeted two specific devices within an unnamed organization. On one of the appliances, artifacts suggesting exploitation and privilege escalation were found in the '/tmp' directory, with a file containing an exploit for CVE-2026-15410. The second device had fewer traces of compromise following a reboot.
The CVE-2026-15409 vulnerability allows for a pre-authentication '/wsproxy' bypass, enabling unauthorized external requests to access services on the appliance. This bypass can be exploited for command injection and privilege escalation. An additional security flaw was discovered that could let attackers bypass authentication by using a product identifier file, although this was not exploited in the documented incident.
The threat actor's activities included leveraging the CouchDB database to read sensitive files and bypass authentication. Rapid7 issued a proof-of-concept exploit demonstrating non-root remote code execution on these devices using this method. Although UTA0533 achieved root access to SonicWall SMA appliances, their lateral movement within the network was reportedly limited.


