← Back to news

Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appliances

Security Affairs20/07/2026, 07:29
Read full article →

Summary

AI-Generated

Key Points:

  • Unknown threat actor UTA0533 exploited two zero-day vulnerabilities (CVE-2026-15409 and CVE-2026-15410) in SonicWall SMA 1000 VPN appliances to gain root access before patches were available.
  • The exploitation allowed attackers to intercept credentials and execute arbitrary commands, posing significant risks to organizations relying on these appliances for authentication.
  • Immediate actions include applying the latest patches from SonicWall, monitoring for signs of unauthorized access, and reviewing logs for suspicious activity related to the affected appliances.

Technical Details: CVE-2026-15409 is a server-side request forgery (SSRF) vulnerability allowing unauthenticated remote access, while CVE-2026-15410 is a post-authentication code injection flaw enabling command execution with elevated privileges.

MITRE ATT&CK Techniques:

  • T1078 - Valid Accounts (Defense Evasion)
  • T1190 - Exploit Public-Facing Application (Initial Access)
  • T1003.001 - OS Credential Dumping: LSASS Memory (Credential Access)
  • T1210 - Exploitation of Remote Services (Execution)

IOCs Mentioned: None mentioned

Join the discussion — sign up to comment, upvote, and save articles.

Discussion

or to comment
Loading...

Loading comments...

Join 5,000+ security professionals

Get access to curated threat intel, upvote articles, join discussions, and build your karma in the SOC community.