Back to advisories

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

UTA0533 has been actively exploiting two zero-day vulnerabilities in SonicWall SMA 1000 series VPN appliances since June 22, 2026, before vendor disclosure. The attacker chains CVE-2026-15409 and CVE-2026-15410 to achieve unauthenticated RCE, privilege escalation, and persistence via custom malware. Any organization running affected SMA appliances is at immediate risk of full compromise and lateral movement.

CRITICALAdvisoryJul 21, 2026
Action required
Immediately identify all SonicWall SMA 1000 series appliances in your environment. Check firewall and VPN logs for exploitation attempts using IOCs from Volexity disclosure. Apply patches from SonicWall as soon as available. Hunt for ROOTRUN, KNUCKLEBALL, ORANGETAIL, and Suo5 proxy artifacts in memory and on disk.
Affected products
SonicWall Secure Mobile Access (SMA) 1000SonicWallVolexity