CVE Tools
Back to feed
Exploited in the wild Secure Mobile Access (SMA) 1000 series UTA0533 zero-day SonicWall rce

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

The Hacker News·By The Hacker News··5 min read
CVE Tools coverage

A new threat actor, tracked as UTA0533, has been actively exploiting two undisclosed vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series devices since June 22, 2026. These zero-days—CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 (CVSS 7.2)—were used to gain root access and deploy custom malware on compromised appliances. Researchers from Volexity discovered the attacks during an incident response investigation and confirmed that the vulnerabilities were chained together to allow arbitrary command execution. SonicWall has since released patches for both issues. Attackers leveraged these flaws to install persistent backdoors, steal credentials, and maintain long-term access to vulnerable systems.