As cited
Copy frozen at (site build).
vulnerabilities
Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation
In early July 2026, incident responders at Volexity discovered that threat actor UTA0533 had exploited multiple zero-day vulnerabilities in SonicWall Secure Mobile Access VPN appliances, including a server-side request forgery (SSRF) flaw and command injection vulnerability affecting the 1000 series models. Analysis of compromised devices revealed the attacker had deployed custom malware and gained remote code execution through a chain of exploits beginning in late June 2026. SonicWall released patches addressing CVE-2026-15409 and CVE-2026-15410 in versions 12.4.3-03453 and 12.5.0-02835.
Why it matters: Organizations running SonicWall SMA VPN appliances face active exploitation of zero-day vulnerabilities by a tracked threat actor; immediate patching to the latest firmware versions and investigation of logs for suspicious /wsproxy requests are required to detect and remediate potential compromises.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation
Volexity discovered that threat actor UTA0533 exploited multiple zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series appliances through a server-side request forgery (SSRF) and command injection attack chain. SonicWall patched CVE-2026-15409 and CVE-2026-15410 in versions 12.4.3-03453 and 12.5.0-02835 after disclosure on July 14, 2026, with the earliest compromise observed on June 22, 2026. Analysis of logs, memory, and disk images revealed the threat actor deployed custom malware and maintained backdoor access via web shells on the affected virtual private network (VPN) appliances.
Why it matters: Organizations running SonicWall SMA 1000 series devices must immediately patch to the hotfix versions to prevent remote code execution and lateral movement into internal networks; monitor extraweb access logs for /wsproxy requests with negative bmID values and internal port access as indicators of active exploitation.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation
Volexity discovered that threat actor UTA0533 exploited multiple zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series appliances through a server-side request forgery (SSRF) and command injection attack chain. SonicWall patched CVE-2026-15409 and CVE-2026-15410 in versions 12.4.3-03453 and 12.5.0-02835 after disclosure on July 14, 2026, with the earliest compromise observed on June 22, 2026. Analysis of logs, memory, and disk images revealed the threat actor deployed custom malware and maintained backdoor access via web shells on the affected virtual private network (VPN) appliances.
Why it matters: Organizations running SonicWall SMA 1000 series devices must immediately patch to the hotfix versions to prevent remote code execution and lateral movement into internal networks; monitor extraweb access logs for /wsproxy requests with negative bmID values and internal port access as indicators of active exploitation.
- Source published
- First seen by Cybersecurity Tracker