A recent zero-day campaign has been uncovered, targeting SonicWall VPN appliances, specifically the SMA 1000 series, by exploiting two previously unknown vulnerabilities, CVE-2026-15409 and CVE-2026-15410. These vulnerabilities, with CVSS scores of 10.0 and 7.2 respectively, were chained together by the threat actor, tracked as UTA0533, to gain root-level access on the devices. The campaign, which began on June 22, 2026, was discovered by Volexity during an incident response investigation at a compromised organization1. The vulnerabilities were exploited before patches were available, highlighting the importance of proactive security measures. The disclosure of CVE-2026-15409, in particular, expands the active attack surface, making it crucial for organizations to prioritize their exposure and exploitation evidence. This campaign's success underscores the need for swift patching and robust security protocols to prevent similar attacks, making it essential for practitioners to reevaluate their VPN appliance security.