Find notable cyber news and cases, enriched with sources, timelines, and signals.

SonicWall SMA1000 SSRF and code injection flaws (multiple vulnerabilities)

Vulnerability
First reported
Last updated
Happening score
H score 48
2 unique sources, 4 articles

Summary

Hide ▲

SonicWall SMA1000 vulnerabilities CVE-2026-15409 and CVE-2026-15410 were exploited as zero-days against SMA1000 Secure Mobile Access appliances, with SonicWall releasing fixes in 12.4.3-03453 and 12.5.0-02835. Volexity later attributed the campaign to UTA0533 and said the earliest observed compromise was June 22, 2026. The actor chained the flaws to reach root on compromised VPN appliances and deployed custom malware including KNUCKLEBALL, Suo5, ORANGETAIL, and ROOTRUN. SonicWall said the flaws were actively exploited, and CISA placed them in the KEV catalog.

Related Happenings

CISA Microsoft SharePoint hardening guidance for exploited zero-days

Advisory/Mitigation
H score56 First: 15.07.2026 17:07 Last: 15.07.2026 17:07 Sources 1

About this happening: CISA’s Microsoft SharePoint servers hardening guidance responds to newly disclosed zero-day vulnerabilities that can be exploited remotely, creating immediate risk for sup...

CISA KEV catalog addition for SonicWall SMA 1000 flaws

Public Sector Action
H score34 First: 15.07.2026 08:30 Last: 15.07.2026 08:30 Sources 1

How related: The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add the two flaws to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 17, 2026.

About this happening: CISA added CVE-2026-15409 and CVE-2026-15410 affecting SonicWall SMA 1000 appliances to the KEV catalog, turning the flaws into a federal remediation priority for...

BRICKSTORM, PLENET, and AGENTPSD Linux appliance deployment

Malware Activity
H score40 First: 08.06.2026 13:27 Last: 08.06.2026 13:27 Sources 1

About this happening: The deployment of BRICKSTORM, PLENET (aka GRIMBOLT), and AGENTPSD on Linux appliances expanded operator access with backdoor, proxying, remote command ex...

SonicWall MySonicWall cloud backup breach exposing firewall backup files

Data Leak
H score40 First: 29.01.2026 19:57 Last: 29.01.2026 19:57 Sources 1

About this happening: SonicWall said a state-sponsored threat actor stole firewall configuration backup files from its MySonicWall cloud backup service in a September security breac...

Marquis Software Solutions hit by ransomware attack

Incident
H score59 First: 29.01.2026 19:57 Last: 29.01.2026 19:57 Sources 1

About this happening: Marquis Software Solutions disclosed that its August 14, 2025 ransomware attack exposed personal data tied to 74 U.S. banks and credit unions and affected over 400,0...

Latest development: 18.03.2026 17:32

Marquis, a Texas-based financial services provider, disclosed that a ransomware gang stole personal and financial data from 672,075 people after an August 14, 2025 attack on a compromised SonicWall firewall, and the incident disrupted operations at 74 banks across the United States; breach notifications were filed in early December, and affected files were reviewed on December 10, 2025.

Timeline

  1. 19.07.2026 16:18 2 articles · 9d ago

    UTA0533 exploits SonicWall SMA1000 zero-days for root access

    Technical Analysis Update

    UTA0533 abused CVE-2026-15409 and CVE-2026-15410 against SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances on June 22, 2026, writing /usr/bin/xzfind as ROOTRUN and /usr/lib/python3.11/site-packages/deploy_new.py as KNUCKLEBALL to establish persistence, inject Suo5 and ORANGETAIL, and escalate to root on the compromised appliances.

    Show sources
  2. 15.07.2026 00:23 3 articles · 13d ago

    SonicWall warns of active zero-day exploitation of SMA1000 flaws

    Initial Disclosure

    SonicWall warns that threat actors are exploiting CVE-2026-15409 and CVE-2026-15410 in zero-day attacks against SMA1000 devices. CVE-2026-15409 is a critical SSRF flaw in the Appliance Work Place interface, and CVE-2026-15410 is a high-severity post-authentication code injection flaw in the Appliance Management Console; fixes are available in platform-hotfix 12.4.3-03453 and 12.5.0-02835, and SonicWall shares indicators of compromise for affected appliances.

    Show sources
  3. 15.07.2026 00:23 1 articles · 13d ago

    Federal agencies face July 17, 2026 deadline for affected SMA1000 systems

    Legal Policy Action Update

    Federal agencies have until July 17, 2026 to secure affected SMA1000 systems under Binding Operational Directive 26-04 or discontinue use of the product if mitigations cannot be applied. The deadline creates a separate compliance obligation for U.S. government users of the vulnerable appliances.

    Show sources