Recently, two vulnerabilities in the SonicWall SMA1000 were revealed to have been exploited in zero-day attacks for several weeks, enabling threat actors to install tailored malware on affected VPN devices.
Last week, SonicWall issued a warning regarding the active exploitation of two previously unknown vulnerabilities in an exploit chain impacting SMA1000 Secure Mobile Access appliances.
The vulnerabilities, identified as CVE-2026-15409, a critical server-side request forgery (SSRF) issue, and CVE-2026-15410, a high-severity command injection vulnerability, affect the SMA1000 models 6210, 7210, and 8200v.
SonicWall has released patches in versions 12.4.3-03453 and 12.5.0-02835, urging users to apply the updates without delay.
While SonicWall confirmed the exploitation of these flaws as zero-days, they did not provide specifics on how the attackers gained access to the devices.
A recent report from incident response firm Volexity, which assisted SonicWall in the investigation, outlined the complete exploitation chain and the methods used by threat actors to install custom malware on compromised SMA1000 appliances.
Volexity’s report indicates that a previously unidentified threat actor, referred to as UTA0533, began exploiting the vulnerabilities as early as June 22, weeks prior to SonicWall’s public disclosure of the issues.
According to Volexity,
Source: Original article
