{"id":1865,"date":"2026-07-19T15:46:05","date_gmt":"2026-07-19T15:46:05","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1865"},"modified":"2026-07-19T15:46:05","modified_gmt":"2026-07-19T15:46:05","slug":"sonicwall-sma-zero-days-exploited-before-disclosure-to-gain-root-access","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1865","title":{"rendered":"SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jul 19, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Network Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgLomYbwprpYWKVxrxKRh3hFiGRWdVOb7WAVbhJjf_fYQAba4wVZT1PpwWAL-ZDb40MZp9T43-dj8Fru-eOjiKcrAoh5sOdyKGUUAVwK9iifXl70EvgORPztxnvYXc9HA8trGKcRZGob8DYJxUZBg0zlZFUTiRGPXGFheSbKLUoG53kZ9HR6XxyJs9GEtcA\/s1700-e365\/sma-sonicwall.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026.<\/p>\n<p>Cybersecurity company Volexity is tracking the activity under the moniker <strong>UTA0533<\/strong>. The discovery was made following an incident response investigation earlier this month. The impacted organization has not been identified.<\/p>\n<p>\u00abThis threat actor was observed using multiple zero-day exploits, malware designed specifically for SonicWall SMA VPN appliances, as well as other attacker tradecraft,\u00bb security researchers Sean Koessel and Steven Adair <a href=\"https:\/\/www.volexity.com\/blog\/2026\/07\/17\/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation\/\" target=\"_blank\">said<\/a> in an analysis.<\/p>\n<p>The vulnerabilities in question are CVE-2026-15409 (CVSS score: 10.0) and CVE-2026-15410 (CVSS score: 7.2), both of which could be chained to facilitate arbitrary command execution and take over susceptible devices. Patches for both the vulnerabilities were released by SonicWall this week.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-vuln-protection-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjQl2axNwsfhbXOFynrg_uAZsvHi3OvNGSA8KJO-BKR8Xm3x7yjKV3EvfY4v5mwXx6LF0uWFb9h9d9iAV_Pi-YYhqimX9wx4OaLdDJEdR215Xrxq_PAtXkaLfQso4pTSjbj6fvh_ZTliLpzWZSZfcoZgyXtKwhN-SSDDlmbtUqGLshc0KqYQGWYHMN52Sl1\/s728-e100\/zz-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Two SonicWall SMA VPN devices belonging to the compromised entity have been identified. The sequence of actions undertaken by the threat actor in these appliances are listed below &#8211;<\/p>\n<ul>\n<li>\n    Appliance 1:<\/p>\n<ul>\n<li>Writing an ELF Executable named \u00ab\/usr\/bin\/xzfind\u00bb on June 22, 2026. The file is a <a href=\"https:\/\/man7.org\/linux\/man-pages\/man2\/setuid.2.html\" target=\"_blank\">setuid<\/a> binary called ROOTRUN that allows an unprivileged user to execute arbitrary commands as root.<\/li>\n<li>Writing a second file name \u00ab\/usr\/lib\/python3.11\/site-packages\/deploy_new.py\u00bb (aka KNUCKLEBALL), which contains two embedded JAR archives that are injected into a legitimate SonicWall process. The two payloads are Suo5, an open-source HTTP proxy, and a Behinder-like custom Java web shell dubbed ORANGETAIL. The JAR files enable the attackers to interact with them via internet-accessible URI paths: \u00ab\/workplace\/error.jsp\u00bb and \u00ab\/workplace\/dialogs\/errorDialog.jsp.\u00bb<\/li>\n<li>Establishing persistence by modifying the legitimate \u00ab\/etc\/init.d\/workplace startup\u00bb script by means of the Python script downloaded in the previous step.<\/li>\n<li>Modifying the NGINX Unit configuration file at \u00ab\/var\/lib\/unit\/conf.json\u00bb to add two routes leading to Suo5 and ORANGETAIL.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul>\n<li>\n    Appliance 2:<\/p>\n<ul>\n<li>Making the same modifications to \u00ab\/var\/lib\/unit\/conf.json\u00bb identified on the first appliance, although the routes did not return valid responses.<\/li>\n<li>Creating multiple files in the \u00ab\/var\/tmp\u00bb directory, including one (\u00ablib.sh\u00bb) that launches tcpdump to inspect unencrypted LDAP traffic to extract usernames and passwords.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>The second appliance is said to have fewer artifacts following a reboot on July 2, 2026, resulting in the removal of any memory-resident artifacts and backdoors.<\/p>\n<p>Volexity said it identified additional files associated with exploitation and privilege escalation in the \u00ab\/tmp\u00bb folder of the first appliance, with one file (\u00ab\/tmp\/hypdate.b64\u00bb) featuring an exploit for CVE-2026-15410.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjVSvWdDhj669NoarIq0SE_9SNYEWErRWAfBLuI1OAm_zDHC0lSOHu8RkPsXXA82FEvWq0pubiPSJNegxDjEz2J18JGvrHk7GiIlgkLyW1PmK8shzQ5JlG5Durxe3RZISPLWPrDVmoMJqOvYF6XSok3-13Mife4FyatYnHR1iTqdrs3ETcWRbWCWuDWT9hB\/s1700-e365\/sonic.jpg\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjVSvWdDhj669NoarIq0SE_9SNYEWErRWAfBLuI1OAm_zDHC0lSOHu8RkPsXXA82FEvWq0pubiPSJNegxDjEz2J18JGvrHk7GiIlgkLyW1PmK8shzQ5JlG5Durxe3RZISPLWPrDVmoMJqOvYF6XSok3-13Mife4FyatYnHR1iTqdrs3ETcWRbWCWuDWT9hB\/s1700-e365\/sonic.jpg\" alt=\"\" border=\"0\" data-original-height=\"1067\" data-original-width=\"2302\"\/><\/a><\/div>\n<p>\u00abThe files in \/tmp were owned by the unprivileged account used by the appliance&#8217;s internal database service,\u00bb the researchers explained. \u00abThis indicated the threat actor could write and likely execute files through that service context.\u00bb<\/p>\n<p>Further analysis of the logs and system memory led to the discovery of CVE-2026-15409, which has been described as a pre-authentication \u00ab\/wsproxy\u00bb bypass that allows an unauthenticated external request to establish a WebSocket tunnel to localhost-only services on the appliance. Specifically, it involves issuing a request with a User-Agent of SMA Connect Agent and a bmID value that begins with -3389.<\/p>\n<p>The external access can be abused by the threat actor to access methods defined in the \u00absysCtrl\u00bb endpoint, providing a pathway for deeper access by exploiting command injection, privilege escalation, and code execution flaws in the SMA control service (i.e., CVE-2026-15410).<\/p>\n<p>Also flagged as part of the analysis is a separate security defect that can permit an attacker to bypass the authentication to the SMA control service (\u00abctrl-service\u00bb). Because the Basic authentication password is derived from the appliance-local hardware identifier (\u00ab\/sys\/class\/dmi\/id\/product_uuid\u00bb), an attacker with knowledge of this UUID can determine the password needed for authentication.<\/p>\n<p>What makes this trivial is that the \u00abproduct_uuid\u00bb file is readable by anyone, thereby allowing an unprivileged user to obtain the value and figure out the password. That said, the UUID value is only observed for physical devices, meaning virtual appliances are not impacted.<\/p>\n<p>\u00abIt should be noted that this authentication bypass does not appear to have been used in the observed incident,\u00bb Volexity said. \u00abInstead, the attacker abused a different vulnerability to read the &#8216;product_uuid&#8217; file\u00bb<\/p>\n<p>In addition, UTA0533 has been linked to the exploitation of CouchDB, a database that comes installed as part of the SMA appliance and is accessible via localhost. Although the exact operation carried out by the threat actor remains unclear, signs point to the use of the CouchDB user to read the \u00abproduct_uuid\u00bb file and ultimately sidestep authentication.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/sygnia-cyber-response-d-2\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjHcvlLVmAqlffm6kG54_0cGVf8WfcgzqT9B0fBSizSSeIjh8tBepXnrf6BMqKiG344WgqNejcRtEFKT1PmOzQNQBhdmu2iz9Po10z0SSDlFuZ37iip2uYibJDoxTEkbUI7Bx8NJM2Io_z_nl5p4YA-ZhqFLfi0GW1axyu-lQx-iytCn9RGSJ2iqCwdyv8m\/s1600\/sy-d-2.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abWith this capability, an attacker can reach and exploit less-hardened services running on the appliance, such as the Erlang application on localhost:1050 or the ctrl-service application on localhost:8188,\u00bb Rapid7 <a href=\"https:\/\/www.rapid7.com\/blog\/post\/etr-rapid7-mdr-team-discovers-new-sonicwall-sma1000-zero-days-being-actively-exploited-cve-2026-15409-cve-2026-15410\/\" target=\"_blank\">said<\/a>.<\/p>\n<p>A proof-of-concept (PoC) exploit <a href=\"https:\/\/github.com\/remmons-r7\/rapid7-CVE-2026-15409\" target=\"_blank\">released<\/a> by the cybersecurity vendor establishes non-root remote code execution on SonicWall SMA 1000 devices by implementing the Erlang protocol expected by localhost:1050 and tunneling it through the WebSocket for file read-write and arbitrary code execution via RPC calls.<\/p>\n<p>In all, the entire exploitation chain unfolds as follows &#8211;<\/p>\n<ul>\n<li>Send an unauthenticated \u00ab\/wsproxy\u00bb request with the User-Agent string containing SMA Connect Agent and URI parameter starting with bmID=-3389.<\/li>\n<li>Establish a WebSocket tunnel to localhost-only services.<\/li>\n<li>Make calls to CouchDB to read, write files as the \u00abcouchdb\u00bb user.<\/li>\n<li>Stage a file in \u00ab\/tmp\u00bb as the \u00abcouchdb\u00bb user that will read the \/sys\/class\/dmi\/id\/product_uuid file once executed by exploiting CVE-2026-15409.<\/li>\n<li>Escalate to root by exploiting CVE-2026-15410, a path traversal flaw in the \u00abremove_hotfix\u00bb workflow of \u00abctrl-service\u00bb and obtain command execution with elevated privileges.<\/li>\n<\/ul>\n<p>\u00abUTA0533 combined multiple zero-day vulnerabilities to compromise SonicWall SMA VPN appliances and obtain root-level access,\u00bb Volexity said. \u00abWith root access, the threat actor could access stored or cached credentials, capture network traffic, and potentially intercept credentials processed by the appliances.\u00bb<\/p>\n<p>\u00abAlthough UTA0533 demonstrated significant capability in compromising the SonicWall appliances, available evidence suggests the threat actor was less successful moving laterally or gaining access to other systems.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jul 19, 2026Vulnerability \/ Network Security A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1866,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[130,799,128,580,61,820,2538,53],"class_list":["post-1865","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-access","tag-disclosure","tag-exploited","tag-gain","tag-root","tag-sma","tag-sonicwall","tag-zerodays"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1865","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1865"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1865\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1866"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1865"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1865"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1865"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}