
CVE-2026-15409, CVE-2026-15410: SonicWall SMA — Root Access via Zero-Days (July 2026)
CVE-2026-15409, CVE-2026-15410 — SonicWall SMA
CVE-2026-15409 and CVE-2026-15410 are critical zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. Both were exploited in the wild by threat actor UTA0533 prior to public disclosure, enabling root-level compromise of affected devices. No CVSS score is published yet, but exploitation is confirmed and ongoing.
Attack Vector
UTA0533 leveraged multiple zero-day exploits to gain root access on SonicWall SMA 1000 appliances. Attackers deployed custom malware and established persistence using files such as /usr/bin/xzfind, /usr/lib/python3.11/site-packages/deploy_new.py, and /etc/init.d/workplace startup. Malicious scripts and configuration changes were observed in /var/lib/unit/conf.json, /var/tmp/lib.sh, and /tmp/hypdate.b64. The attack chain enabled credential theft, network traffic interception, and persistent control of the appliance. Lateral movement beyond the SMA device was not observed.
Who Is at Risk
All organizations running SonicWall SMA 1000 series VPN appliances are at risk, regardless of region or deployment type. SonicWall is the confirmed affected vendor. There is no evidence of impact beyond the appliance itself, but compromise of stored or processed credentials is likely.
Patch & Mitigate
- Patch: Apply SonicWall security updates for SMA 1000 series as soon as released. Monitor vendor advisories for urgent hotfixes.
- Workaround: If patching is not possible, restrict management access to trusted networks and monitor for abnormal device behavior.
- Detect: Review appliances for the presence of IOCs: /usr/bin/xzfind, /usr/lib/python3.11/site-packages/deploy_new.py, /etc/init.d/workplace startup, /var/lib/unit/conf.json, /var/tmp/lib.sh, /tmp/hypdate.b64. Audit logs for unauthorized root access or configuration changes.
MITRE ATT&CK
- TA0001 — Initial Access: Attackers exploited zero-days to gain initial foothold on SMA appliances.
- TA0004 — Privilege Escalation: Exploits granted root-level privileges on the device.
- TA0009 — Collection: Attackers accessed credentials and captured network traffic processed by the appliance.
Source: https://thehackernews.com/2026/07/sonicwall-sma-zero-days-exploited.html
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

