SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026.
Intelligence analysis by Llama

A threat actor exploited SonicWall SMA VPN appliances as zero-days prior their public disclosure, gaining root access and potentially compromising sensitive data. Patches for the vulnerabilities were released by SonicWall this week.
Imagine you have a super-secure lock on your front door, but someone finds a way to pick the lock without you knowing. That's what happened with the SonicWall SMA VPN appliances. A bad guy found a way to get into the system without being detected, and that's a big problem.
Analysis
A $60B Vote of Confidence
The recent exploitation of SonicWall SMA VPN appliances by a previously undocumented threat actor has raised concerns about the security of these devices. The threat actor, tracked by Volexity as UTA0533, exploited the vulnerabilities in question, CVE-2026-15409 and CVE-2026-15410, to gain root access and potentially compromise sensitive data. The patches for both vulnerabilities were released by SonicWall this week, but the incident highlights the importance of timely patching and vulnerability disclosure in preventing potential security breaches.
Why Cursor?
The exploitation of SonicWall SMA VPN appliances is a reminder that even the most secure systems can be vulnerable to attacks. The threat actor exploited multiple zero-day exploits, malware designed specifically for SonicWall SMA VPN appliances, and other attacker tradecraft to gain access to the devices. The vulnerabilities in question, CVE-2026-15409 and CVE-2026-15410, could be chained to facilitate arbitrary command execution and take over susceptible devices.
The Road Ahead
The incident highlights the importance of regular security updates and patches to prevent potential security breaches. It also emphasizes the need for timely vulnerability disclosure to prevent the exploitation of known vulnerabilities. The patches for the vulnerabilities in question were released by SonicWall this week, and it is essential for users to apply these patches to prevent potential security breaches.
Key points
- A previously undocumented threat actor exploited SonicWall SMA VPN appliances as zero-days prior their public disclosure.
- The threat actor gained root access and potentially compromised sensitive data.
- Patches for the vulnerabilities were released by SonicWall this week.
- The incident highlights the importance of timely patching and vulnerability disclosure in preventing potential security breaches.
The patches for the vulnerabilities were released by SonicWall this week, and it is expected that users will apply these patches to prevent potential security breaches. This should help to prevent similar incidents in the future.
The exploitation of SonicWall SMA VPN appliances highlights the importance of timely patching and vulnerability disclosure in preventing potential security breaches. If users do not apply the patches, they may be vulnerable to similar attacks in the future.



