Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SonicWall Zero-Days Exploited for Root Access

SonicWall Zero-Days Exploited for Root Access

Posted on July 19, 2026 By CWS

A previously unknown cyber threat group has been identified exploiting zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN devices. This activity, traced back to June 22, 2026, occurred before these vulnerabilities were publicly disclosed. The cybersecurity firm Volexity has attributed these actions to a group it has codenamed UTA0533 following an incident response investigation earlier this month. The target organization remains undisclosed.

Volexity researchers, Sean Koessel and Steven Adair, reported that the threat actor utilized multiple zero-day exploits and custom malware designed specifically for SonicWall SMA VPN appliances. The exploits involved vulnerabilities CVE-2026-15409 with a critical CVSS score of 10.0 and CVE-2026-15410, which scored 7.2. These vulnerabilities were leveraged to execute arbitrary commands and seize control of vulnerable devices. SonicWall has since released patches to address these security flaws.

Details of the Exploitation

The attack on two identified SonicWall SMA VPN devices involved sophisticated techniques to gain root access. On the first appliance, the threat actor deployed an ELF executable and created a Python-based script, both facilitating the execution of unauthorized commands. Embedded JAR files, Suo5 and ORANGETAIL, were used to control legitimate SonicWall processes and establish persistence by altering startup scripts and configuration files.

The second appliance saw similar configuration changes, though its routes did not yield valid responses. Additionally, files created in the “/var/tmp” directory, including a script utilizing tcpdump, were intended to capture unencrypted network traffic for credential harvesting. A reboot on July 2, 2026, resulted in the removal of transient artifacts from this device.

Potential Impact and Analysis

Volexity’s investigation revealed further exploitation activities, such as the use of the CouchDB database to bypass authentication mechanisms. The attacker exploited local file access to read the “product_uuid” file, which allowed them to deduce passwords for the SMA control service. This access pathway was, however, not actively used in the incident.

The exploitation chain involved issuing unauthenticated requests to establish WebSocket tunnels, enabling further interactions with local services and elevating privileges through CVE-2026-15410, a path traversal vulnerability. This comprehensive attack strategy underscores the significant threat posed by zero-day vulnerabilities and underscores the need for prompt patching and robust security measures.

Future Implications and Recommendations

The ability of UTA0533 to exploit multiple zero-day vulnerabilities highlights the evolving nature of cyber threats and the importance of continuous monitoring and incident response capabilities. While the group demonstrated proficiency in breaching SonicWall appliances, evidence suggests a limited ability to infiltrate other network systems.

Organizations utilizing SonicWall devices are advised to apply the latest patches promptly and review their security posture to mitigate potential risks. Enhanced network monitoring and thorough incident response strategies are crucial in defending against sophisticated cyber threat actors.

The Hacker News Tags:CVE-2026-15409, CVE-2026-15410, Cybersecurity, Exploit, Malware, network security, Patches, root access, SMA VPN, SonicWall, UTA0533, Vulnerability, zero-day

Post navigation

Previous Post: Russian Hackers Exploit ClickFix CAPTCHAs in Ukraine
Next Post: Cybersecurity Insights: Microsoft Patch, WordPress Risk

Related Posts

Blind Eagle’s Five Clusters Target Colombia Using RATs, Phishing Lures, and Dynamic DNS Infra Blind Eagle’s Five Clusters Target Colombia Using RATs, Phishing Lures, and Dynamic DNS Infra The Hacker News
X Warns Users With Security Keys to Re-Enroll Before November 10 to Avoid Lockouts X Warns Users With Security Keys to Re-Enroll Before November 10 to Avoid Lockouts The Hacker News
Popular Chrome Extensions Leak API Keys, User Data via HTTP and Hardcoded Credentials Popular Chrome Extensions Leak API Keys, User Data via HTTP and Hardcoded Credentials The Hacker News
Magento Flaw Risks RCE and Account Security Magento Flaw Risks RCE and Account Security The Hacker News
Malicious Chrome Extensions Threaten Business Security Malicious Chrome Extensions Threaten Business Security The Hacker News
Microsoft Highlights Hotel Phishing Threat with Node.js Microsoft Highlights Hotel Phishing Threat with Node.js The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Malicious RubyGems Packages Threaten Developer Security
  • Critical WordPress Flaws WP2Shell Actively Exploited
  • Hugging Face AI Platform Breached by Autonomous AI
  • Critical NGINX Flaw Enables Remote Code Execution
  • Critical NGINX Bug Poses Remote Code Execution Risk

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Malicious RubyGems Packages Threaten Developer Security
  • Critical WordPress Flaws WP2Shell Actively Exploited
  • Hugging Face AI Platform Breached by Autonomous AI
  • Critical NGINX Flaw Enables Remote Code Execution
  • Critical NGINX Bug Poses Remote Code Execution Risk

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark