INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
SonicWall SMA Zero-Days Exploit Vulnerability
| 2026-07-20 22:23 CRITICAL MEDIUM EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The SonicWall SMA1000 Secure Mobile Access appliances have been compromised by a threat actor using multiple zero-day exploits, including two previously undisclosed vulnerabilities in an exploit chain that affected the devices. The attackers exploited CVE-2026-15409 and CVE-2026-15410 to establish unauthenticated WebSocket tunnels to services accessible only from the appliance itself, allowing them to execute commands as root and gain full control of the device. Additionally, they installed a custom malware dropper called KNUCKLEBALL under the file name '[IOC HIDDEN • LOGIN REQUIRED]' after obtaining the appliance's product_uuid through exploitation of CVE-2026-15410 command injection vulnerability. The attackers also modified the appliance's nginx configuration to expose an ORANGETAIL webshell remotely and used ROOTRUN, a privilege-escalation tool, to execute commands as root. This threat actor was observed using multiple zero-day exploits, including Sou5 (agent_wp8.jar) and ORANGETAIL (agent_wp9.jar), designed for SonicWall SMA1000 appliances.
Technical Mitigations AI-generated
* Implement a secure patching strategy for all vulnerable devices, including regular updates and patches to address known vulnerabilities before they can be exploited.
* Conduct thorough vulnerability scanning and penetration testing on new or untested systems to identify potential zero-day exploits before they can be used against them.
* Educate users about the importance of keeping software up-to-date and patched, as well as the risks associated with using outdated or unpatched devices.
* Implement a robust incident response plan that includes procedures for responding to zero-day attacks, including containment, eradication, recovery, and post-incident activities.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
sy•••••.execremovehotfix
ct•••••.log
li•••••.sh
co•••••.json
er•••••.jsp
er•••••.jsp
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-56155CVE-2026-56155
CVE-2026-15409CVE-2026-15409
CVE-2025-23006CVE-2025-23006
CVE-2026-15410CVE-2026-15410
CVE-2026-56164CVE-2026-56164
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
governmentgovernment
Incident Timeline
late 2021
Seventeen defects affecting SonicWall products were discovered and added to the US-CISA known exploited vulnerabilities catalog in late 2021.
June 22, 2026
Threat actors used an ELF executable to write a malicious program on June 22, 2026.
Click on any entity below to view its context and source!
organisation
SonicWall Secure Mobile Access
A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026.
organisation
SMA
A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026.
general_metric
1000 series
A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026.
general_metric
1 Appliance
The sequence of actions undertaken by the threat actor in these appliances are listed below -
Appliance 1:
Writing an ELF Executable named "/usr/bin/xzfind" on June 22, 2026.
June 22
Rapid7 researchers disclosed both vulnerabilities on June 22.
Click on any entity below to view its context and source!
organisation
CyberScoop
Rapid7 researchers told CyberScoop both vulnerabilities were first exploited June 22.
July 2, 2026
Threat actors exploited a zero-day vulnerability in the SonicWall SMA Zero-Day Exploit Vulnerability.
2026/07/13
Threat actors exploited two previously undisclosed vulnerabilities in SonicWall SMA1000 Secure Mobile Access appliances.
Click on any entity below to view its context and source!
organisation
Secure Mobile Access
Last week, SonicWall warned that threat actors were
actively exploiting two previously undisclosed vulnerabilities
in an exploit chain that affected SMA1000 Secure Mobile Access appliances.
July 14, 2026
Threat actors exploited a zero-day vulnerability in the SonicWall SMA1000 appliances.
July 14
Threat actors exploited a zero-day vulnerability in SonicWall's SMA 1000 Series appliances to gain unauthorized access and connect to ransomware.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-15409
Connection to Inc Ransomware
The Cybersecurity and Infrastructure Security Agency's (CISA) added CVE-2026-15409 and CVE-2026-15410 to its
Known Exploited Vulnerabilities
(KEV) catalog on July 14.
On July 14, the cybersecurity vendor SonicWall published a
security advisory
regarding two vulnerabilities in its SMA 1000 Series appliances, CVE-2026-15409 and CVE-2026-15410.
vulnerability
CVE-2026-15410
Connection to Inc Ransomware
The Cybersecurity and Infrastructure Security Agency's (CISA) added CVE-2026-15409 and CVE-2026-15410 to its
Known Exploited Vulnerabilities
(KEV) catalog on July 14.
On July 14, the cybersecurity vendor SonicWall published a
security advisory
regarding two vulnerabilities in its SMA 1000 Series appliances, CVE-2026-15409 and CVE-2026-15410.
tactic
Ransomware
Connection to Inc Ransomware
The Cybersecurity and Infrastructure Security Agency's (CISA) added CVE-2026-15409 and CVE-2026-15410 to its
Known Exploited Vulnerabilities
(KEV) catalog on July 14.
tactic
T1588.006 - Vulnerabilities
Connection to Inc Ransomware
The Cybersecurity and Infrastructure Security Agency's (CISA) added CVE-2026-15409 and CVE-2026-15410 to its
Known Exploited Vulnerabilities
(KEV) catalog on July 14.
attribution
Connection to Inc Ransomware
Connection to Inc Ransomware
The Cybersecurity and Infrastructure Security Agency's (CISA) added CVE-2026-15409 and CVE-2026-15410 to its
Known Exploited Vulnerabilities
(KEV) catalog on July 14.
attribution
Known Exploited
Connection to Inc Ransomware
The Cybersecurity and Infrastructure Security Agency's (CISA) added CVE-2026-15409 and CVE-2026-15410 to its
Known Exploited Vulnerabilities
(KEV) catalog on July 14.
attribution
KEV
Connection to Inc Ransomware
The Cybersecurity and Infrastructure Security Agency's (CISA) added CVE-2026-15409 and CVE-2026-15410 to its
Known Exploited Vulnerabilities
(KEV) catalog on July 14.
organisation
CVE-2026
On July 14, the cybersecurity vendor SonicWall published a
security advisory
regarding two vulnerabilities in its SMA 1000 Series appliances, CVE-2026-15409 and CVE-2026-15410.
general_metric
1000 series
On July 14, the cybersecurity vendor SonicWall published a
security advisory
regarding two vulnerabilities in its SMA 1000 Series appliances, CVE-2026-15409 and CVE-2026-15410.
Jul 15, 2026
Threat actors exploited a previously unknown vulnerability in the SonicWall SMA Zero-Day Exploit.
July 15
Threat actors exploited a zero-day vulnerability in the SonicWall SMA Zero-Day Exploit Vulnerability.
July 17, 2026
SonicWall's SMA Zero-Day Exploit Vulnerability was identified and publicly disclosed by SecurityAffairs, prompting the US Cybersecurity and Infrastructure Security Agency (CISA) to add it to its Known Exploited Vulnerabilities catalog.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-56155
CISA orders federal agencies to urgently fix the vulnerabilities by July 17, 2026, except
CVE-2026-56155
, which must be addressed by July 28, 2026
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking,
CISA
)
attribution
SecurityAffairs
CISA orders federal agencies to urgently fix the vulnerabilities by July 17, 2026, except
CVE-2026-56155
, which must be addressed by July 28, 2026
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking,
CISA
)
tactic
T1588.006 - Vulnerabilities
SonicWall also acknowledged the contributions of Volexity's Sean Koessel and Steven Adair to help advance the internal investigation and identify an additional IoC.
The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to
add
the two flaws to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 17, 2026.
attribution
Known Exploited
SonicWall also acknowledged the contributions of Volexity's Sean Koessel and Steven Adair to help advance the internal investigation and identify an additional IoC.
The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to
add
the two flaws to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 17, 2026.
attribution
KEV
SonicWall also acknowledged the contributions of Volexity's Sean Koessel and Steven Adair to help advance the internal investigation and identify an additional IoC.
The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to
add
the two flaws to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 17, 2026.
attribution
FCEB
SonicWall also acknowledged the contributions of Volexity's Sean Koessel and Steven Adair to help advance the internal investigation and identify an additional IoC.
The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to
add
the two flaws to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 17, 2026.
attribution
Federal Civilian Executive Branch
SonicWall also acknowledged the contributions of Volexity's Sean Koessel and Steven Adair to help advance the internal investigation and identify an additional IoC.
The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to
add
the two flaws to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 17, 2026.
general_metric
26 Binding Operational Directive
Federal agencies have until July 17, 2026, to secure affected systems under Binding Operational Directive (BOD) 26-04 or discontinue use of the product if mitigations cannot be applied.
2026/07/20
SonicWall released patches for the SMA1000 Appliance Management Console vulnerability.
Click on any entity below to view its context and source!
organisation
Secure Mobile Access
Two newly reported vulnerabilities in SonicWall's
Secure Mobile Access
(SMA) appliances have been exploited as zero-days by a major ransomware group.
SonicWall SMA1000 Appliances Code Injection Vulnerability
CVE-2026-56155
Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability
CVE-2026-56164
Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability
This week, SonicWall
confirmed
the active exploitation of two zero-day vulnerabilities affecting Secure Mobile Access (SMA) 1000 appliances.
Ravie Lakshmanan
Jul 15, 2026
Vulnerability / Enterprise Security
SonicWall has
warned
of active exploitation of two zero-day vulnerabilities impacting Secure Mobile Access (SMA) 1000 series appliances, one of which could be exploited to achieve arbitrary command execution.
SonicWall confirmed the active exploitation of two zero-day vulnerabilities affecting Secure Mobile Access (SMA) 1000 appliances.
organisation
SonicWall
Two newly reported vulnerabilities in SonicWall's
Secure Mobile Access
(SMA) appliances have been exploited as zero-days by a major ransomware group.
SonicWall SMA1000 Appliances Code Injection Vulnerability
CVE-2026-56155
Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability
CVE-2026-56164
Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability
This week, SonicWall
confirmed
the active exploitation of two zero-day vulnerabilities affecting Secure Mobile Access (SMA) 1000 appliances.
Ravie Lakshmanan
Jul 15, 2026
Vulnerability / Enterprise Security
SonicWall has
warned
of active exploitation of two zero-day vulnerabilities impacting Secure Mobile Access (SMA) 1000 series appliances, one of which could be exploited to achieve arbitrary command execution.
SonicWall SMA1000 flaws exploited as zero-days to push custom malware.
Patches for both the vulnerabilities were released by SonicWall this week.
SonicWall SMA1000 vulnerabilities in active exploitation.
SonicWall customers under threat as attackers exploit 2 zero-days.
SonicWall warns of active exploitation of two SMA 1000 zero-days.
SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now.
organisation
SMA
Two newly reported vulnerabilities in SonicWall's
Secure Mobile Access
(SMA) appliances have been exploited as zero-days by a major ransomware group.
SonicWall SMA1000 Appliances Code Injection Vulnerability
CVE-2026-56155
Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability
CVE-2026-56164
Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability
This week, SonicWall
confirmed
the active exploitation of two zero-day vulnerabilities affecting Secure Mobile Access (SMA) 1000 appliances.
Ravie Lakshmanan
Jul 15, 2026
Vulnerability / Enterprise Security
SonicWall has
warned
of active exploitation of two zero-day vulnerabilities impacting Secure Mobile Access (SMA) 1000 series appliances, one of which could be exploited to achieve arbitrary command execution.
SonicWall warns of active exploitation of two SMA 1000 zero-days.
organisation
Microsoft
SonicWall SMA1000 Appliances Code Injection Vulnerability
CVE-2026-56155
Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability
CVE-2026-56164
Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability
This week, SonicWall
confirmed
the active exploitation of two zero-day vulnerabilities affecting Secure Mobile Access (SMA) 1000 appliances.
organisation
Vulnerability / Enterprise Security
Ravie Lakshmanan
Jul 15, 2026
Vulnerability / Enterprise Security
SonicWall has
warned
of active exploitation of two zero-day vulnerabilities impacting Secure Mobile Access (SMA) 1000 series appliances, one of which could be exploited to achieve arbitrary command execution.
organisation
CVE-2026
The flaws, tracked as CVE-2026-15409, a critical server-side request forgery (SSRF) vulnerability, and CVE-2026-15410, a high-severity command injection flaw, affect SMA1000 6210, 7210, and 8200v appliances.
SonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day attacks and urges customers to install the newly released security updates.
organisation
WebSocket
"
In an investigation of two compromised appliances, Volexity found that the attackers first exploited CVE-2026-15409 to abuse the SMA1000's '
/wsproxy
' endpoint, allowing them to establish unauthenticated WebSocket tunnels to services that should only have been accessible from the appliance itself.
"
Further examination of the logs and system memory led to the discovery of CVE-2026-15409, which has been described as a pre-authentication "/wsproxy" bypass that allows an unauthenticated external request to establish a WebSocket tunnel to localhost-only services on the appliance.
Customers should review system logs for indicators of compromise, such as unusual requests to login or logout API endpoints, suspicious WebSocket proxy connections, evidence of hotfix rollbacks using path traversal techniques, or unauthorized API routes in the appliance configuration.
organisation
CVE-2026-15409
CVE-2026-15409 is a critical (CVSS 10.0) server-side request forgery (SSRF) vulnerability in the SMA1000 Appliance Work Place interface that allows a remote, unauthenticated attacker to force an appliance to make requests to unintended locations.
organisation
the Appliance Management Console's '
After obtaining the appliance's product_uuid, the attackers exploited the CVE-2026-15410 command injection vulnerability through the Appliance Management Console's '
sysCtrl.execRemoveHotfix
' RPC method, allowing them to execute commands as root and take full control of the appliance.
organisation
RPC
After obtaining the appliance's product_uuid, the attackers exploited the CVE-2026-15410 command injection vulnerability through the Appliance Management Console's '
sysCtrl.execRemoveHotfix
' RPC method, allowing them to execute commands as root and take full control of the appliance.
A proof-of-concept (PoC) exploit
released
by the cybersecurity vendor establishes non-root remote code execution on SonicWall SMA 1000 devices by implementing the Erlang protocol expected by localhost:1050 and tunneling it through the WebSocket for file read-write and arbitrary code execution via RPC calls.
organisation
Gold Eagle Clearinghouse Targets
Related:
Gold Eagle Clearinghouse Targets Security Gap, but How Is Unclear
CVE-2026-15410 earned a lesser but still high 7.2 out of 10 CVSS score, since it requires that an attacker already be able to reach the Appliance Management Console (AMC) — the administrative user interface (UI) for an already accessible device.
organisation
CVSS
Related:
Gold Eagle Clearinghouse Targets Security Gap, but How Is Unclear
CVE-2026-15410 earned a lesser but still high 7.2 out of 10 CVSS score, since it requires that an attacker already be able to reach the Appliance Management Console (AMC) — the administrative user interface (UI) for an already accessible device.
The vendor warned customers that the vulnerability was chained with
CVE-2025-23006
(CVSS score 9.8) in zero-day attacks to escalate privileges.
organisation
Appliance Management Console
Related:
Gold Eagle Clearinghouse Targets Security Gap, but How Is Unclear
CVE-2026-15410 earned a lesser but still high 7.2 out of 10 CVSS score, since it requires that an attacker already be able to reach the Appliance Management Console (AMC) — the administrative user interface (UI) for an already accessible device.
CVE-2026-15410
is a high-severity (CVSS score of 7.2) command injection vulnerability in the Appliance Management Console that can enable arbitrary operating system command execution by an administrator-level user.
In December, SonicWall
urged
customers to address another SMA1000 Appliance Management Console issue that was exploited as a zero-day in attacks in the wild.
organisation
AMC
Related:
Gold Eagle Clearinghouse Targets Security Gap, but How Is Unclear
CVE-2026-15410 earned a lesser but still high 7.2 out of 10 CVSS score, since it requires that an attacker already be able to reach the Appliance Management Console (AMC) — the administrative user interface (UI) for an already accessible device.
The second vulnerability, tracked as CVE-2026-15410 (CVSS score of 7.2), is a post-authentication code injection flaw in the Appliance Management Console (AMC) that a remote authenticated attacker could exploit to execute arbitrary operating system commands as administrator under certain conditions.
A post-authentication code injection vulnerability rooted in the Appliance Management Console (AMC) that a remote authenticated attacker could exploit to execute arbitrary operating system commands as administrator under certain conditions.
organisation
UI
Related:
Gold Eagle Clearinghouse Targets Security Gap, but How Is Unclear
CVE-2026-15410 earned a lesser but still high 7.2 out of 10 CVSS score, since it requires that an attacker already be able to reach the Appliance Management Console (AMC) — the administrative user interface (UI) for an already accessible device.
organisation
the Appliance Management Console
The second vulnerability, tracked as CVE-2026-15410 (CVSS score of 7.2), is a post-authentication code injection flaw in the Appliance Management Console (AMC) that a remote authenticated attacker could exploit to execute arbitrary operating system commands as administrator under certain conditions.
A post-authentication code injection vulnerability rooted in the Appliance Management Console (AMC) that a remote authenticated attacker could exploit to execute arbitrary operating system commands as administrator under certain conditions.
organisation
the SMA1000 Appliance Management Console
CVE-2026-15410 is a high-severity (CVSS 7.2) post-authentication code injection flaw in the SMA1000 Appliance Management Console that could allow a remote authenticated administrator to execute arbitrary operating system commands.
“Post-authentication improper control of generation of code (‘Code Injection’) vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.” continues the advisory.
infrastructure
12.4.3-03453
SonicWall released patches in versions 12.4.3-03453 and 12.5.0-02835, urging customers to install the updates immediately.
The patches are available in the following versions -
12.4.3-03453 (platform-hotfix) and higher versions
12.5.0-02835 (platform-hotfix) and higher versions
Users are also urged to perform a thorough forensic analysis of the system to determine the presence of any indicators of compromise (IoCs) associated with exploitation -
If in extraweb_access.log are mentioned requests to /__api__/login or /__api__/logout with http 200 status
If in extraweb_access.log are mentioned requests to /wsproxy with suspicious host parameters with 101 http status
If in ctrl-service.log are mentioned hotfix rollbacks with path traversal names
If /var/lib/unit/conf.json contains routes for /__api__/login or /__api__/logout (these URIs do not exist in legitimate configuration)
The company addressed the issue in the following versions:
12.4.3-03453 (platform-hotfix) and higher versions.
Fixes are available in platform-hotfix versions 12.4.3-03453 and 12.5.0-02835, and later releases.
infrastructure
12.5.0-02835
SonicWall released patches in versions 12.4.3-03453 and 12.5.0-02835, urging customers to install the updates immediately.
The patches are available in the following versions -
12.4.3-03453 (platform-hotfix) and higher versions
12.5.0-02835 (platform-hotfix) and higher versions
Users are also urged to perform a thorough forensic analysis of the system to determine the presence of any indicators of compromise (IoCs) associated with exploitation -
If in extraweb_access.log are mentioned requests to /__api__/login or /__api__/logout with http 200 status
If in extraweb_access.log are mentioned requests to /wsproxy with suspicious host parameters with 101 http status
If in ctrl-service.log are mentioned hotfix rollbacks with path traversal names
If /var/lib/unit/conf.json contains routes for /__api__/login or /__api__/logout (these URIs do not exist in legitimate configuration)
Fixes are available in platform-hotfix versions 12.4.3-03453 and 12.5.0-02835, and later releases.
12.5.0-02835 (platform-hotfix) and higher versions.
organisation
API
Customers should review system logs for indicators of compromise, such as unusual requests to login or logout API endpoints, suspicious WebSocket proxy connections, evidence of hotfix rollbacks using path traversal techniques, or unauthorized API routes in the appliance configuration.
organisation
PoC
A proof-of-concept (PoC) exploit
released
by the cybersecurity vendor establishes non-root remote code execution on SonicWall SMA 1000 devices by implementing the Erlang protocol expected by localhost:1050 and tunneling it through the WebSocket for file read-write and arbitrary code execution via RPC calls.
The researchers published a proof-of-concept (PoC)
exploit
for the former vulnerability on GitHub.
organisation
SonicWall SMA 1000
A proof-of-concept (PoC) exploit
released
by the cybersecurity vendor establishes non-root remote code execution on SonicWall SMA 1000 devices by implementing the Erlang protocol expected by localhost:1050 and tunneling it through the WebSocket for file read-write and arbitrary code execution via RPC calls.
infrastructure
1000 devices
A proof-of-concept (PoC) exploit
released
by the cybersecurity vendor establishes non-root remote code execution on SonicWall SMA 1000 devices by implementing the Erlang protocol expected by localhost:1050 and tunneling it through the WebSocket for file read-write and arbitrary code execution via RPC calls.
organisation
KNUCKLEBALL
Writing a second file name "/usr/lib/python3.11/site-packages/deploy_new.py" (aka KNUCKLEBALL), which contains two embedded JAR archives that are injected into a legitimate SonicWall process.
KNUCKLEBALL is used to deploy two Java-based malware families named Sou5 (agent_wp8.jar) and ORANGETAIL (agent_wp9.jar), designed for SonicWall SMA1000 appliances.
organisation
JAR
Writing a second file name "/usr/lib/python3.11/site-packages/deploy_new.py" (aka KNUCKLEBALL), which contains two embedded JAR archives that are injected into a legitimate SonicWall process.
organisation
Volexity
In a new report, incident response firm Volexity, which assisted SonicWall in investigating the attacks, detailed the full exploitation chain and how threat actors installed the custom malware on compromised SMA1000 appliances.
organisation
SonicWall SMA VPN
"This threat actor was observed using multiple zero-day exploits, malware designed specifically for SonicWall SMA VPN appliances, as well as other attacker tradecraft.
"This threat actor was observed using multiple zero-day exploits, malware designed specifically for SonicWall SMA VPN appliances, as well as other attacker tradecraft," security researchers Sean Koessel and Steven Adair
said
in an analysis.
organisation
ORANGETAIL
The researchers also found that the attackers modified the appliance's nginx configuration to expose the ORANGETAIL webshell remotely and installed
ROOTRUN
, a privilege-escalation tool that allows commands to be executed as root.
organisation
ROOTRUN
The researchers also found that the attackers modified the appliance's nginx configuration to expose the ORANGETAIL webshell remotely and installed
ROOTRUN
, a privilege-escalation tool that allows commands to be executed as root.
The file is a
setuid
binary called ROOTRUN that allows an unprivileged user to execute arbitrary commands as root.
organisation
EDR
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
organisation
NGINX
Modifying the NGINX Unit configuration file at "/var/lib/unit/conf.json" to add two routes leading to Suo5 and ORANGETAIL.
organisation
SonicWall SMA
Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, SMA 1000)
organisation
Cybersecurity company Volexity
Cybersecurity company Volexity is tracking the activity under the moniker
UTA0533
.
organisation
UUID
Because the Basic authentication password is derived from the appliance-local hardware identifier ("/sys/class/dmi/id/product_uuid"), an attacker with knowledge of this UUID can determine the password needed for authentication.
organisation
SMA Connect
In all, the entire exploitation chain unfolds as follows -
Send an unauthenticated "/wsproxy" request with the User-Agent string containing SMA Connect Agent and URI parameter starting with bmID=-3389.
organisation
bmID=-3389
In all, the entire exploitation chain unfolds as follows -
Send an unauthenticated "/wsproxy" request with the User-Agent string containing SMA Connect Agent and URI parameter starting with bmID=-3389.
financial
40 ransomware attacks
Ten of those defects are known to be used in ransomware campaigns, according to CISA, including a wave of about
40 Akira ransomware attacks
between mid-July and early August.
organisation
CVE-2025
The vendor warned customers that the vulnerability was chained with
CVE-2025-23006
(CVSS score 9.8) in zero-day attacks to escalate privileges.
organisation
the Common Vulnerability Scoring System
It requires no authentication, and it has earned a maximum 10 out of 10 score in the Common Vulnerability Scoring System (CVSS).
organisation
Ivanti
All this might help explain why hackers continually go after SonicWall, exploiting
zero-day vulnerabilities in its products
at a rate similar to other edge devices vendors, like Fortinet and Ivanti.
organisation
Fortinet
All this might help explain why hackers continually go after SonicWall, exploiting
zero-day vulnerabilities in its products
at a rate similar to other edge devices vendors, like Fortinet and Ivanti.
organisation
Deroche
"Simply applying the vendor patch is no longer sufficient if the appliance was already compromised," Rapid7's Deroche emphasizes.
organisation
Counter Threat Unit
Recommended actions
Counter Threat Unit™ (CTU) researchers recommend that organizations identify vulnerable SonicWall appliances in their environments and upgrade as appropriate as soon as possible.
organisation
the SMA1000 Appliance Work Place
“A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface.
infrastructure
12.4.3-03245
The vulnerabilities impact the following software and versions:
Affected Product
Affected Version(s)
SMA1000 Models – 6210, 7210, 8200v
12.4.3-03245, 12.4.3-03387 and 12.4.3-03434 (platform-hotfix)12.5.0-02283, 12.5.0-02624 and 12.5.0-02800 (platform-hotfix)
The vulnerabilities affect SMA1000 models 6210, 7210, and 8200v running platform-hotfix releases 12.4.3-03245, 12.4.3-03387, 12.4.3-03434, 12.5.0-02283, 12.5.0-02624, and 12.5.0-02800.
infrastructure
12.4.3-03387
The vulnerabilities impact the following software and versions:
Affected Product
Affected Version(s)
SMA1000 Models – 6210, 7210, 8200v
12.4.3-03245, 12.4.3-03387 and 12.4.3-03434 (platform-hotfix)12.5.0-02283, 12.5.0-02624 and 12.5.0-02800 (platform-hotfix)
The vulnerabilities affect SMA1000 models 6210, 7210, and 8200v running platform-hotfix releases 12.4.3-03245, 12.4.3-03387, 12.4.3-03434, 12.5.0-02283, 12.5.0-02624, and 12.5.0-02800.
infrastructure
12.4.3-03434
The vulnerabilities impact the following software and versions:
Affected Product
Affected Version(s)
SMA1000 Models – 6210, 7210, 8200v
12.4.3-03245, 12.4.3-03387 and 12.4.3-03434 (platform-hotfix)12.5.0-02283, 12.5.0-02624 and 12.5.0-02800 (platform-hotfix)
The vulnerabilities affect SMA1000 models 6210, 7210, and 8200v running platform-hotfix releases 12.4.3-03245, 12.4.3-03387, 12.4.3-03434, 12.5.0-02283, 12.5.0-02624, and 12.5.0-02800.
infrastructure
12.5.0-02283
The vulnerabilities impact the following software and versions:
Affected Product
Affected Version(s)
SMA1000 Models – 6210, 7210, 8200v
12.4.3-03245, 12.4.3-03387 and 12.4.3-03434 (platform-hotfix)12.5.0-02283, 12.5.0-02624 and 12.5.0-02800 (platform-hotfix)
The vulnerabilities affect SMA1000 models 6210, 7210, and 8200v running platform-hotfix releases 12.4.3-03245, 12.4.3-03387, 12.4.3-03434, 12.5.0-02283, 12.5.0-02624, and 12.5.0-02800.
infrastructure
12.5.0-02624
The vulnerabilities impact the following software and versions:
Affected Product
Affected Version(s)
SMA1000 Models – 6210, 7210, 8200v
12.4.3-03245, 12.4.3-03387 and 12.4.3-03434 (platform-hotfix)12.5.0-02283, 12.5.0-02624 and 12.5.0-02800 (platform-hotfix)
The vulnerabilities affect SMA1000 models 6210, 7210, and 8200v running platform-hotfix releases 12.4.3-03245, 12.4.3-03387, 12.4.3-03434, 12.5.0-02283, 12.5.0-02624, and 12.5.0-02800.
infrastructure
12.5.0-02800
The vulnerabilities impact the following software and versions:
Affected Product
Affected Version(s)
SMA1000 Models – 6210, 7210, 8200v
12.4.3-03245, 12.4.3-03387 and 12.4.3-03434 (platform-hotfix)12.5.0-02283, 12.5.0-02624 and 12.5.0-02800 (platform-hotfix)
The vulnerabilities affect SMA1000 models 6210, 7210, and 8200v running platform-hotfix releases 12.4.3-03245, 12.4.3-03387, 12.4.3-03434, 12.5.0-02283, 12.5.0-02624, and 12.5.0-02800.
organisation
IOC
Sean Koessel and Steven Adair of
Volexity
helped advance PSIRT investigation, leading to the identification of an additional IOC.
organisation
SonicWall Firewall
“Please note that SonicWall Firewall products are not affected by this vulnerability.”
organisation
BleepingComputer
BleepingComputer has contacted SonicWall to clarify the attacks and will update this story if we receive a response.
July 2026
Threat actors exploited a zero-day vulnerability in SonicWall SMA Zero-Day Exploit Vulnerability.
Click on any entity below to view its context and source!
organisation
KEV
Regarding the other two issues added to the KEV catalog this month, Microsoft’s July 2026 Patch Tuesday security updates
fixed
a record 621 CVEs, including two that are being actively exploited as zero-days.
July 28, 2026
Threat actors used a zero-day exploit in the SonicWall SMA Zero-Day Vulnerability to target users.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-56155
CISA orders federal agencies to urgently fix the vulnerabilities by July 17, 2026, except
CVE-2026-56155
, which must be addressed by July 28, 2026
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking,
CISA
)
attribution
SecurityAffairs
CISA orders federal agencies to urgently fix the vulnerabilities by July 17, 2026, except
CVE-2026-56155
, which must be addressed by July 28, 2026
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking,
CISA
)
Tactical Metrics
Metrics
infrastructure
12.4.3-03453
Software Version
Click for context!
SonicWall released patches in versions 12.4.3-03453 and 12.5.0-02835, urging customers to install the updates immediately.
The patches are available in the following versions -
12.4.3-03453 (platform-hotfix) and higher versions
12.5.0-02835 (platform-hotfix) and higher versions
Users are also urged to perform a thorough forensic analysis of the system to dete…
The company addressed the issue in the following versions:
12.4.3-03453 (platform-hotfix) and higher versions.
Fixes are available in platform-hotfix versions 12.4.3-03453 and 12.5.0-02835, and later releases.
Metrics
infrastructure
12.5.0-02835
Software Version
SonicWall released patches in versions 12.4.3-03453 and 12.5.0-02835, urging customers to install the updates immediately.
The patches are available in the following versions -
12.4.3-03453 (platform-hotfix) and higher versions
12.5.0-02835 (platform-hotfix) and higher versions
Users are also urged to perform a thorough forensic analysis of the system to dete…
12.5.0-02835 (platform-hotfix) and higher versions.
Fixes are available in platform-hotfix versions 12.4.3-03453 and 12.5.0-02835, and later releases.
Metrics
infrastructure
1,000
Devices
…of-concept (PoC) exploit
released
by the cybersecurity vendor establishes non-root remote code execution on SonicWall SMA 1000 devices by implementing the Erlang protocol expected by localhost:1050 and tunneling it through the WebSocket for file…
Metrics
infrastructure
Ivanti
Affected Product
All this might help explain why hackers continually go after SonicWall, exploiting
zero-day vulnerabilities in its products
at a rate similar to other edge devices vendors, like Fortinet and Ivanti.
Metrics
financial
40
Ransomware Attacks
Ten of those defects are known to be used in ransomware campaigns, according to CISA, including a wave of about
40 Akira ransomware attacks
between mid-July and early August.
Metrics
infrastructure
12.4.3-03245
Software Version
…ities impact the following software and versions:
Affected Product
Affected Version(s)
SMA1000 Models – 6210, 7210, 8200v
12.4.3-03245, 12.4.3-03387 and 12.4.3-03434 (platform-hotfix)12.5.0-02283, 12.5.0-02624 and 12.5.0-02800 (platform-hotfix)
The vulnerabilities affect SMA1000 models 6210, 7210, and 8200v running platform-hotfix releases 12.4.3-03245, 12.4.3-03387, 12.4.3-03434, 12.5.0-02283, 12.5.0-02624, and 12.5.0-02800.
Metrics
infrastructure
12.4.3-03387
Software Version
…ities impact the following software and versions:
Affected Product
Affected Version(s)
SMA1000 Models – 6210, 7210, 8200v
12.4.3-03245, 12.4.3-03387 and 12.4.3-03434 (platform-hotfix)12.5.0-02283, 12.5.0-02624 and 12.5.0-02800 (platform-hotfix)
The vulnerabilities affect SMA1000 models 6210, 7210, and 8200v running platform-hotfix releases 12.4.3-03245, 12.4.3-03387, 12.4.3-03434, 12.5.0-02283, 12.5.0-02624, and 12.5.0-02800.
Metrics
infrastructure
12.4.3-03434
Software Version
…ities impact the following software and versions:
Affected Product
Affected Version(s)
SMA1000 Models – 6210, 7210, 8200v
12.4.3-03245, 12.4.3-03387 and 12.4.3-03434 (platform-hotfix)12.5.0-02283, 12.5.0-02624 and 12.5.0-02800 (platform-hotfix)
The vulnerabilities affect SMA1000 models 6210, 7210, and 8200v running platform-hotfix releases 12.4.3-03245, 12.4.3-03387, 12.4.3-03434, 12.5.0-02283, 12.5.0-02624, and 12.5.0-02800.
Metrics
infrastructure
12.5.0-02283
Software Version
…ities impact the following software and versions:
Affected Product
Affected Version(s)
SMA1000 Models – 6210, 7210, 8200v
12.4.3-03245, 12.4.3-03387 and 12.4.3-03434 (platform-hotfix)12.5.0-02283, 12.5.0-02624 and 12.5.0-02800 (platform-hotfix)
The vulnerabilities affect SMA1000 models 6210, 7210, and 8200v running platform-hotfix releases 12.4.3-03245, 12.4.3-03387, 12.4.3-03434, 12.5.0-02283, 12.5.0-02624, and 12.5.0-02800.
Metrics
infrastructure
12.5.0-02624
Software Version
…ities impact the following software and versions:
Affected Product
Affected Version(s)
SMA1000 Models – 6210, 7210, 8200v
12.4.3-03245, 12.4.3-03387 and 12.4.3-03434 (platform-hotfix)12.5.0-02283, 12.5.0-02624 and 12.5.0-02800 (platform-hotfix)
The vulnerabilities affect SMA1000 models 6210, 7210, and 8200v running platform-hotfix releases 12.4.3-03245, 12.4.3-03387, 12.4.3-03434, 12.5.0-02283, 12.5.0-02624, and 12.5.0-02800.
Metrics
infrastructure
12.5.0-02800
Software Version
…ities impact the following software and versions:
Affected Product
Affected Version(s)
SMA1000 Models – 6210, 7210, 8200v
12.4.3-03245, 12.4.3-03387 and 12.4.3-03434 (platform-hotfix)12.5.0-02283, 12.5.0-02624 and 12.5.0-02800 (platform-hotfix)
The vulnerabilities affect SMA1000 models 6210, 7210, and 8200v running platform-hotfix releases 12.4.3-03245, 12.4.3-03387, 12.4.3-03434, 12.5.0-02283, 12.5.0-02624, and 12.5.0-02800.
Intelligence Sources
BleepingComputer
2026-07-20
Sophos News
2026-07-15
The Hacker News
2026-07-19
Dark Reading
2026-07-17
Inc Ransomware Exploits SonicWall SMA Zero-Days
Dark Reading
Security Affairs
2026-07-15
SonicWall warns of active exploitation of two SMA 1000 zero-days
Security Affairs
The Hacker News
2026-07-15
CyberScoop
2026-07-15
BleepingComputer
2026-07-14
Security Affairs
2026-07-15
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-07-21T06:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
50x
organisation
Identified Entity
Secure Mobile Access
entity
22x
timeline
Temporal Reference
June 22, 2026
date
11x
attribution
Attributing Entity
Connection to Inc Ransomware
authority
8x
infrastructure
Software Version
12.4.3-03453
version
6x
tactic
Cyber Operation Type
Privilege Escalation
tactic
5x
vulnerability
Exploited CVE
CVE-2026-15409
cve
5x
tactic
MITRE ATT&CK Technique
T1059.006 - Python
technique
3x
vulnerability
CVSS Score
10
score
2x
general metric
%
54
%
2x
general metric
Score
7
score
2x
general metric
Appliance
2
appliance
Contextual Telemetry
Context Block
19 METRICS
general metric
June
22
june
infrastructure
Devices
1,000
devices
general metric
Escalate
15,410
escalate
general metric
Series
1,000
series
industry
Targeted Sector
Government
sector
general metric
Cvss Score
10
cvss score
infrastructure
Affected Product
Ivanti
software
general metric
Insufficient Granularity
56,164
insufficient granularity
target region
Target Country
United States
country
financial
Ransomware Attacks
40
ransomware attacks
general metric
Units
5,000
units
general metric
Http
200
http
general metric
Http Status
101
http status
general metric
Jul
15
jul
general metric
Sma1000 Models
6,210
sma1000 models
general metric
Platform Hotfix)12.5.0
2,283
platform hotfix)12.5.0
general metric
Hotfix)12.5.0
2,800
hotfix)12.5.0
general metric
Binding Operational Directive
26
binding operational directive
general metric
Sma
100
sma
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.