SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
ID: a827ddc6-a435-5f31-a163-5f4e450808ee
STIX ID: report--a827ddc6-a435-5f31-a163-5f4e450808ee
Feed Name: The Hacker News
Volexity reported that a previously undocumented threat actor named UTA0533 exploited zero-day flaws in SonicWall SMA 1000 VPN appliances (CVE-2026-15409 and CVE-2026-15410) prior to public disclosure to gain unauthenticated access, tunnel to localhost services, escalate privileges to root, and deploy custom payloads (a setuid ELF named ROOTRUN, a Python dropper embedding two JARs including an HTTP proxy and a Java web shell). The analysis describes the full exploitation chain, persistence modifications, artifacts and IOCs (paths, filenames, config changes), proof-of-concept exploits, and that SonicWall released patches this week; evidence suggests successful compromise of at least two appliances with limited lateral movement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
