A recent zero-day campaign has been uncovered, targeting SonicWall VPN appliances, specifically the SMA 1000 series, by exploiting two previously unknown vulnerabilities, CVE-2026-15409 and CVE-2026-15410. These vulnerabilities, with CVSS scores of 10.0 and 7.2 respectively, were chained together by the threat actor, tracked as UTA0533, to gain root-level access on the devices. The campaign, which began on June 22, 2026, was discovered by Volexity during an incident response investigation at a compromised organization1. The vulnerabilities were exploited before patches were available, highlighting the importance of proactive security measures. The disclosure of CVE-2026-15409, in particular, expands the active attack surface, making it crucial for organizations to prioritize their exposure and exploitation evidence. This campaign's success underscores the need for swift patching and robust security protocols to prevent similar attacks, making it essential for practitioners to reevaluate their VPN appliance security.
Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appliances
⚠️ Critical Alert
Why This Matters
CVE-2026-15409 disclosure expands the active attack surface — prioritize based on your exposure and exploitation evidence.
References
- SecurityAffairs. (2026, July 20). Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appliances. *SecurityAffairs*. https://securityaffairs.com/195626/hacking/volexity-uncovers-zero-day-campaign-targeting-sonicwall-vpn-appliances.html
Original Source
SecurityAffairs
Read original →