← BACK TO FEED
TAG

sonicwall1 articles

Unknown Threat Actor Chained SonicWall Zero-Days to Root Before Anyone Knew They Existed

A previously unknown threat actor (UTA0533) exploited two zero-day vulnerabilities — CVE-2026-15409 and CVE-2026-15410 — in SonicWall SMA 1000 series VPN appliances before patches were publicly released, chaining them together to achieve root-level access on compromised devices. The attacker deployed custom malware, including a web shell and HTTP proxy tool, modified startup scripts for persistence, and used packet capture utilities to steal LDAP credentials. While UTA0533 demonstrated advanced capability in compromising the appliances, evidence suggests they had limited success in moving laterally to other systems on the network.

19 Jul 2026