⌁ CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

July 19, 2026

A previously undocumented threat actor, tracked as UTA0533 by Volexity, exploited two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances before patches were publicly disclosed. The vulnerabilities, CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 (CVSS 7.2), were chained to achieve arbitrary command execution and root-level access on affected devices.

The attack chain began on June 22, 2026, with the threat actor writing an ELF executable named “/usr/bin/xzfind” (a setuid binary called ROOTRUN) and a Python script “/usr/lib/python3.11/site-packages/deploy_new.py” (KNUCKLEBALL) containing two JAR archives: Suo5 (an HTTP proxy) and ORANGETAIL (a Behinder-like Java web shell). Persistence was established by modifying the startup script and NGINX Unit configuration to expose the payloads via URI paths.

On a second appliance, the threat actor created files in “/var/tmp” including “lib.sh” to capture unencrypted LDAP traffic. Volexity identified additional artifacts in “/tmp” owned by the unprivileged database service account, indicating exploitation through that context. CVE-2026-15409 is a pre-authentication “/wsproxy” bypass allowing WebSocket tunnels to localhost services, while CVE-2026-15410 is a path traversal flaw in the “remove_hotfix” workflow enabling privilege escalation.

An authentication bypass was also noted, where the Basic auth password is derived from the hardware UUID file readable by anyone, though not used in this incident. Rapid7 released a PoC exploit establishing non-root RCE via Erlang protocol tunneling. Volexity noted that while UTA0533 demonstrated significant capability, lateral movement was limited.

CVEs: CVE-2026-15409, CVE-2026-15410

Attack groups: UTA0533

Malware: KNUCKLEBALL, Suo5, ORANGETAIL, ROOTRUN

Companies: SonicWall, Volexity, Rapid7

Products: SonicWall SMA 1000 series