CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2789

As cited

Copy frozen at (site build).

vulnerabilities

Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation

In early July 2026, incident responders at Volexity discovered that threat actor UTA0533 had exploited multiple zero-day vulnerabilities in SonicWall Secure Mobile Access VPN appliances, including a server-side request forgery (SSRF) flaw and command injection vulnerability affecting the 1000 series models. Analysis of compromised devices revealed the attacker had deployed custom malware and gained remote code execution through a chain of exploits beginning in late June 2026. SonicWall released patches addressing CVE-2026-15409 and CVE-2026-15410 in versions 12.4.3-03453 and 12.5.0-02835.

Why it matters: Organizations running SonicWall SMA VPN appliances face active exploitation of zero-day vulnerabilities by a tracked threat actor; immediate patching to the latest firmware versions and investigation of logs for suspicious /wsproxy requests are required to detect and remediate potential compromises.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation

Volexity discovered that threat actor UTA0533 exploited multiple zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series appliances through a server-side request forgery (SSRF) and command injection attack chain. SonicWall patched CVE-2026-15409 and CVE-2026-15410 in versions 12.4.3-03453 and 12.5.0-02835 after disclosure on July 14, 2026, with the earliest compromise observed on June 22, 2026. Analysis of logs, memory, and disk images revealed the threat actor deployed custom malware and maintained backdoor access via web shells on the affected virtual private network (VPN) appliances.

Why it matters: Organizations running SonicWall SMA 1000 series devices must immediately patch to the hotfix versions to prevent remote code execution and lateral movement into internal networks; monitor extraweb access logs for /wsproxy requests with negative bmID values and internal port access as indicators of active exploitation.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation

Volexity discovered that threat actor UTA0533 exploited multiple zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series appliances through a server-side request forgery (SSRF) and command injection attack chain. SonicWall patched CVE-2026-15409 and CVE-2026-15410 in versions 12.4.3-03453 and 12.5.0-02835 after disclosure on July 14, 2026, with the earliest compromise observed on June 22, 2026. Analysis of logs, memory, and disk images revealed the threat actor deployed custom malware and maintained backdoor access via web shells on the affected virtual private network (VPN) appliances.

Why it matters: Organizations running SonicWall SMA 1000 series devices must immediately patch to the hotfix versions to prevent remote code execution and lateral movement into internal networks; monitor extraweb access logs for /wsproxy requests with negative bmID values and internal port access as indicators of active exploitation.

VendorsSonicWall
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary