Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SonicWall Zero-Days Exploited for Root Access

SonicWall Zero-Days Exploited for Root Access

Posted on July 19, 2026 By CWS

A previously unknown cyber threat group has been identified exploiting zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN devices. This activity, traced back to June 22, 2026, occurred before these vulnerabilities were publicly disclosed. The cybersecurity firm Volexity has attributed these actions to a group it has codenamed UTA0533 following an incident response investigation earlier this month. The target organization remains undisclosed.

Volexity researchers, Sean Koessel and Steven Adair, reported that the threat actor utilized multiple zero-day exploits and custom malware designed specifically for SonicWall SMA VPN appliances. The exploits involved vulnerabilities CVE-2026-15409 with a critical CVSS score of 10.0 and CVE-2026-15410, which scored 7.2. These vulnerabilities were leveraged to execute arbitrary commands and seize control of vulnerable devices. SonicWall has since released patches to address these security flaws.

Details of the Exploitation

The attack on two identified SonicWall SMA VPN devices involved sophisticated techniques to gain root access. On the first appliance, the threat actor deployed an ELF executable and created a Python-based script, both facilitating the execution of unauthorized commands. Embedded JAR files, Suo5 and ORANGETAIL, were used to control legitimate SonicWall processes and establish persistence by altering startup scripts and configuration files.

The second appliance saw similar configuration changes, though its routes did not yield valid responses. Additionally, files created in the “/var/tmp” directory, including a script utilizing tcpdump, were intended to capture unencrypted network traffic for credential harvesting. A reboot on July 2, 2026, resulted in the removal of transient artifacts from this device.

Potential Impact and Analysis

Volexity’s investigation revealed further exploitation activities, such as the use of the CouchDB database to bypass authentication mechanisms. The attacker exploited local file access to read the “product_uuid” file, which allowed them to deduce passwords for the SMA control service. This access pathway was, however, not actively used in the incident.

The exploitation chain involved issuing unauthenticated requests to establish WebSocket tunnels, enabling further interactions with local services and elevating privileges through CVE-2026-15410, a path traversal vulnerability. This comprehensive attack strategy underscores the significant threat posed by zero-day vulnerabilities and underscores the need for prompt patching and robust security measures.

Future Implications and Recommendations

The ability of UTA0533 to exploit multiple zero-day vulnerabilities highlights the evolving nature of cyber threats and the importance of continuous monitoring and incident response capabilities. While the group demonstrated proficiency in breaching SonicWall appliances, evidence suggests a limited ability to infiltrate other network systems.

Organizations utilizing SonicWall devices are advised to apply the latest patches promptly and review their security posture to mitigate potential risks. Enhanced network monitoring and thorough incident response strategies are crucial in defending against sophisticated cyber threat actors.

The Hacker News Tags:CVE-2026-15409, CVE-2026-15410, Cybersecurity, Exploit, Malware, network security, Patches, root access, SMA VPN, SonicWall, UTA0533, Vulnerability, zero-day

Post navigation

Previous Post: Russian Hackers Exploit ClickFix CAPTCHAs in Ukraine
Next Post: Cybersecurity Insights: Microsoft Patch, WordPress Risk

Related Posts

UNC1549 Hacks 34 Devices in 11 Telecom Firms via LinkedIn Job Lures and MINIBIKE Malware UNC1549 Hacks 34 Devices in 11 Telecom Firms via LinkedIn Job Lures and MINIBIKE Malware The Hacker News
Addressing Unanswered SOC Alerts in Cybersecurity Addressing Unanswered SOC Alerts in Cybersecurity The Hacker News
New MODBEACON RAT Leverages Encrypted C2 Traffic New MODBEACON RAT Leverages Encrypted C2 Traffic The Hacker News
CL-STA-0969 Installs Covert Malware in Telecom Networks During 10-Month Espionage Campaign CL-STA-0969 Installs Covert Malware in Telecom Networks During 10-Month Espionage Campaign The Hacker News
Fortinet SSL VPNs Hit by Global Brute-Force Wave Before Attackers Shift to FortiManager Fortinet SSL VPNs Hit by Global Brute-Force Wave Before Attackers Shift to FortiManager The Hacker News
0-Days, LinkedIn Spies, Crypto Crimes, IoT Flaws and New Malware Waves 0-Days, LinkedIn Spies, Crypto Crimes, IoT Flaws and New Malware Waves The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft’s KB5121767 Update Resolves Dell USB-C Issues
  • LG Monitor Software May Install Adware Silently
  • Microsoft to End OneDrive Sync Support for Windows 10
  • Paidwork Data Breach Exposes Millions of Users’ Data
  • FakeGit Exploits GitHub to Distribute SmartLoader Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft’s KB5121767 Update Resolves Dell USB-C Issues
  • LG Monitor Software May Install Adware Silently
  • Microsoft to End OneDrive Sync Support for Windows 10
  • Paidwork Data Breach Exposes Millions of Users’ Data
  • FakeGit Exploits GitHub to Distribute SmartLoader Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark