Recently identified SonicWall SMA1000 vulnerabilities have been exploited in zero-day attacks, enabling attackers to install custom malware on compromised VPN appliances over the past several weeks.
SonicWall alerted customers about the active exploitation of two undisclosed vulnerabilities in the SMA1000 Secure Mobile Access appliance. These vulnerabilities are crucial and require immediate attention.
The first vulnerability is CVE-2026-15409, a critical server-side request forgery (SSRF) vulnerability, while the second is CVE-2026-15410, a high-severity command injection flaw. Both affect the SMA1000 models 6210, 7210, and 8200v.
SonicWall has released critical patches for versions 12.4.3-03453 and 12.5.0-02835 and strongly urges customers to apply these updates without delay.
While SonicWall confirmed the exploitation of these flaws as zero-day vulnerabilities, specific details regarding the initial compromise remain undisclosed.
A recent report from the incident response firm Volexity, which assisted in the investigation of the SonicWall attack, elaborates on the complete exploit chain and how custom malware was deployed on compromised SMA1000 appliances.
Volexity’s Investigation into the Zero-Day Attack Chain
Volexity identified an undisclosed threat actor, tracked as UTA0533, which began exploiting the vulnerabilities on June 22, weeks prior to SonicWall’s public disclosure.
“Volexity’s log and memory analysis revealed the existence of UTA0533.” Read the full report here.
The attacker utilized multiple zero-day exploits and malware specifically designed for SonicWall SMA VPN appliances, with the earliest indication of compromise observed on June 22, 2026.
Upon investigating two compromised appliances, Volexity determined that attackers first exploited CVE-2026-15409, allowing unauthenticated WebSocket tunnels to internal services, including CouchDB and the VPN device management service.
This access enabled attackers to query CouchDB, retrieving the appliance’s product_uuid, necessary for advancing to the second phase of the attack. The exact method of exploiting CouchDB remains unknown.
With the product_uuid in hand, the attacker accessed the sysCtrl.execRemoveHotfix RPC method, executing commands as root and gaining full control of the appliance.
The threat actor deployed custom malware named KNUCKLEBALL, with the filename deploy_new.py.
KNUCKLEBALL facilitated the deployment of two Java-based malware families: Sou5 (agent_wp8.jar) and ORANGETAIL (agent_wp9.jar), specifically crafted for SonicWall SMA1000 appliances.

Source: Volexity
Volexity states that Sou5 functions as a reverse proxy, enabling attackers to tunnel traffic through a compromised appliance and maintain hidden access to internal resources.
Conversely, ORANGETAIL is a custom Java web shell that lets attackers send encrypted Java payloads to execute dynamically within an HTTP session.
Additionally, researchers found that attackers modified the appliance’s nginx configuration to expose and install the ORANGETAIL WebShell, allowing command execution as root via the route run privilege escalation tool.
Volexity noted that while the operation displayed remarkable technical sophistication, the attackers experienced limited success in infiltrating victims’ internal networks.
Security teams document only 54% of successful attacks, issuing warnings on merely 14%. The remaining threats go undetected within the environment.
Picus’ whitepaper illustrates how to test your SIEM and EDR rules using breach and attack simulations to ensure no threats linger undetected.
Source: www.bleepingcomputer.com




