logo

Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation

ID: 07e451dc-59b5-5815-ba6c-5fde77afb743

STIX ID: report--07e451dc-59b5-5815-ba6c-5fde77afb743

Feed Name: Volexity Blog

Threat Score
90/100

Date Published: 2026-07-17

Date Updated: 2026-07-18

...
...

Volexity investigated compromises of SonicWall SMA 1000-series appliances (earliest observed June 22, 2026) where threat actor UTA0533 abused multiple zero-day flaws — including a wsproxy bypass and a sysCtrl path-traversal leading to execution — to gain root, deploy a setuid privilege escalation binary and Java-based webshells (Suo5/ORANGETAIL), and capture credentials and network traffic; the report provides timelines, IOCs (logs, file hashes, IPs), exploitation chain reconstruction, and mitigation/detection recommendations including hotfix versions and YARA signatures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.