SonicWall SMA1000 SSRF and code injection flaws (multiple vulnerabilities)
Vulnerability
Summary
Hide ▲
Show ▼
SonicWall SMA1000 vulnerabilities CVE-2026-15409 and CVE-2026-15410 were exploited as zero-days against SMA1000 Secure Mobile Access appliances, with SonicWall releasing fixes in 12.4.3-03453 and 12.5.0-02835. Volexity later attributed the campaign to UTA0533 and said the earliest observed compromise was June 22, 2026. The actor chained the flaws to reach root on compromised VPN appliances and deployed custom malware including KNUCKLEBALL, Suo5, ORANGETAIL, and ROOTRUN. SonicWall said the flaws were actively exploited, and CISA placed them in the KEV catalog.
Related Happenings
CISA Microsoft SharePoint hardening guidance for exploited zero-days
Advisory/Mitigation
H score56
First: 15.07.2026 17:07
Last: 15.07.2026 17:07
Sources 1
About this happening:
CISA’s Microsoft SharePoint servers hardening guidance responds to newly disclosed zero-day vulnerabilities that can be exploited remotely, creating immediate risk for sup...
CISA Microsoft SharePoint hardening guidance for exploited zero-days
Advisory/MitigationAbout this happening: CISA’s Microsoft SharePoint servers hardening guidance responds to newly disclosed zero-day vulnerabilities that can be exploited remotely, creating immediate risk for sup...
CISA KEV catalog addition for SonicWall SMA 1000 flaws
Public Sector Action
H score34
First: 15.07.2026 08:30
Last: 15.07.2026 08:30
Sources 1
How related:
The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add the two flaws to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 17, 2026.
About this happening:
CISA added CVE-2026-15409 and CVE-2026-15410 affecting SonicWall SMA 1000 appliances to the KEV catalog, turning the flaws into a federal remediation priority for...
CISA KEV catalog addition for SonicWall SMA 1000 flaws
Public Sector ActionHow related: The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add the two flaws to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 17, 2026.
About this happening: CISA added CVE-2026-15409 and CVE-2026-15410 affecting SonicWall SMA 1000 appliances to the KEV catalog, turning the flaws into a federal remediation priority for...
BRICKSTORM, PLENET, and AGENTPSD Linux appliance deployment
Malware Activity
H score40
First: 08.06.2026 13:27
Last: 08.06.2026 13:27
Sources 1
About this happening:
The deployment of BRICKSTORM, PLENET (aka GRIMBOLT), and AGENTPSD on Linux appliances expanded operator access with backdoor, proxying, remote command ex...
BRICKSTORM, PLENET, and AGENTPSD Linux appliance deployment
Malware ActivityAbout this happening: The deployment of BRICKSTORM, PLENET (aka GRIMBOLT), and AGENTPSD on Linux appliances expanded operator access with backdoor, proxying, remote command ex...
SonicWall MySonicWall cloud backup breach exposing firewall backup files
Data Leak
H score40
First: 29.01.2026 19:57
Last: 29.01.2026 19:57
Sources 1
About this happening:
SonicWall said a state-sponsored threat actor stole firewall configuration backup files from its MySonicWall cloud backup service in a September security breac...
SonicWall MySonicWall cloud backup breach exposing firewall backup files
Data LeakAbout this happening: SonicWall said a state-sponsored threat actor stole firewall configuration backup files from its MySonicWall cloud backup service in a September security breac...
Marquis Software Solutions hit by ransomware attack
Incident
H score59
First: 29.01.2026 19:57
Last: 29.01.2026 19:57
Sources 1
About this happening:
Marquis Software Solutions disclosed that its August 14, 2025 ransomware attack exposed personal data tied to 74 U.S. banks and credit unions and affected over 400,0...
Marquis Software Solutions hit by ransomware attack
IncidentAbout this happening: Marquis Software Solutions disclosed that its August 14, 2025 ransomware attack exposed personal data tied to 74 U.S. banks and credit unions and affected over 400,0...
Latest development: 18.03.2026 17:32
Marquis, a Texas-based financial services provider, disclosed that a ransomware gang stole personal and financial data from 672,075 people after an August 14, 2025 attack on a compromised SonicWall firewall, and the incident disrupted operations at 74 banks across the United States; breach notifications were filed in early December, and affected files were reviewed on December 10, 2025.
Timeline
-
19.07.2026 16:18 2 articles · 9d ago
UTA0533 exploits SonicWall SMA1000 zero-days for root access
Technical Analysis UpdateUTA0533 abused CVE-2026-15409 and CVE-2026-15410 against SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances on June 22, 2026, writing /usr/bin/xzfind as ROOTRUN and /usr/lib/python3.11/site-packages/deploy_new.py as KNUCKLEBALL to establish persistence, inject Suo5 and ORANGETAIL, and escalate to root on the compromised appliances.
Show sources
- SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access — thehackernews.com — 19.07.2026 16:18
- SonicWall SMA1000 flaws exploited as zero-days to push custom malware — www.bleepingcomputer.com — 21.07.2026 01:23
-
15.07.2026 00:23 3 articles · 13d ago
SonicWall warns of active zero-day exploitation of SMA1000 flaws
Initial DisclosureSonicWall warns that threat actors are exploiting CVE-2026-15409 and CVE-2026-15410 in zero-day attacks against SMA1000 devices. CVE-2026-15409 is a critical SSRF flaw in the Appliance Work Place interface, and CVE-2026-15410 is a high-severity post-authentication code injection flaw in the Appliance Management Console; fixes are available in platform-hotfix 12.4.3-03453 and 12.5.0-02835, and SonicWall shares indicators of compromise for affected appliances.
Show sources
- SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now — www.bleepingcomputer.com — 15.07.2026 00:23
- SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now — www.bleepingcomputer.com — 15.07.2026 00:23
- Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands — thehackernews.com — 15.07.2026 08:30
-
15.07.2026 00:23 1 articles · 13d ago
Federal agencies face July 17, 2026 deadline for affected SMA1000 systems
Legal Policy Action UpdateFederal agencies have until July 17, 2026 to secure affected SMA1000 systems under Binding Operational Directive 26-04 or discontinue use of the product if mitigations cannot be applied. The deadline creates a separate compliance obligation for U.S. government users of the vulnerable appliances.
Show sources
- SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now — www.bleepingcomputer.com — 15.07.2026 00:23