CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2802

As cited

Copy frozen at (site build).

vulnerabilities

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

A threat actor tracked as UTA0533 exploited zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances to achieve root access before the vulnerabilities were publicly disclosed on June 22, 2026. Volexity discovered the activity during an incident response investigation. The attacker gained access to affected SMA devices prior to patches becoming available.

Why it matters: Organizations running SonicWall SMA 1000 series appliances face active exploitation risk; practitioners should prioritize patching and investigate logs for UTA0533 indicators of compromise, particularly if devices were accessible before June 22, 2026.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

A previously unknown threat actor tracked as UTA0533 exploited SonicWall Secure Mobile Access (SMA) 1000 series virtual private network (VPN) appliances as zero-day vulnerabilities before public disclosure on June 22, 2026. Volexity discovered the activity during incident response work and attributed it to root access attempts on the affected devices.

Why it matters: Organizations running SonicWall SMA 1000 series VPN appliances need to determine if they were compromised before the June 22, 2026 disclosure and apply patches immediately, as an active threat actor had working exploits.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

A previously unknown threat actor tracked as UTA0533 exploited SonicWall Secure Mobile Access (SMA) 1000 series virtual private network (VPN) appliances as zero-day vulnerabilities before public disclosure on June 22, 2026. Volexity discovered the activity during incident response work and attributed it to root access attempts on the affected devices.

Why it matters: Organizations running SonicWall SMA 1000 series VPN appliances need to determine if they were compromised before the June 22, 2026 disclosure and apply patches immediately, as an active threat actor had working exploits.

VendorsSonicWall
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary