SonicWall has issued an urgent warning for customers to immediately patch two zero-day vulnerabilities affecting its Secure Mobile Access (SMA) 1000 series appliances. The vulnerabilities, CVE-2026-15409 and CVE-2026-15410, are being actively exploited in the wild by threat actors. The attack involves chaining the two flaws to achieve unauthenticated remote code execution (RCE) on vulnerable internet-facing devices. According to security firm Rapid7, which discovered the in-the-wild attacks, exploitation began as early as June 22, 2026. The compromise of these critical network security appliances can serve as an initial access point for broader network intrusion, credential theft, and potential ransomware deployment. Both vulnerabilities have been added to the CISA Known Exploited Vulnerabilities (KEV) catalog.
The attack relies on a two-stage exploit chain:
CVE-2026-15409: Server-Side Request Forgery (SSRF)
CVE-2026-15410: Code Injection
root privileges. By leveraging the SSRF flaw to reach the necessary internal endpoint, an attacker can trigger this code injection vulnerability without prior authentication, effectively combining the two into an unauthenticated RCE chain.The vulnerabilities affect the following SonicWall products running specific firmware versions:
Organizations using these appliances for remote access are at high risk, as these devices are by nature internet-exposed.
Active exploitation has been confirmed in the wild by Rapid7's MDR team since at least June 22, 2026, nearly three weeks before patches were released on July 14, 2026. Attackers are using the exploit chain to gain a foothold on the appliances, from which they can extract credentials, active user session data, and MFA configurations. This information is highly valuable for facilitating lateral movement and deploying ransomware within the victim's network.
CISA has added both CVEs to its KEV catalog and has set a patching deadline of July 17, 2026, for Federal Civilian Executive Branch agencies, underscoring the extreme urgency.
Security teams may want to hunt for the following patterns to identify potential compromise:
/cgi-bin/viewcert/tmp/sslvpn_webapp.pysh, bash, or wget./cgi-bin/viewcert endpoint, especially those that appear anomalous or originate from untrusted sources. Look for evidence of command injection in request parameters if possible.sslvpn_webapp.py process spawning shell commands (sh, bash, curl, wget) or other unexpected binaries. This aligns with D3FEND Process Analysis.Inc Ransomware and UTA0533 identified exploiting SonicWall SMA zero-days. New TTPs, custom malware, and critical remediation advice on full device reset provided.
New intelligence reveals the SonicWall SMA zero-days (CVE-2026-15409, CVE-2026-15410) are actively exploited by Inc Ransomware and the sophisticated group UTA0533. UTA0533 deploys custom malware including KNUCKLEBALL, ORANGETAIL web shell, and ROOTRUN for persistence and credential theft via LDAP sniffing. Critical remediation guidance now states that applying patches alone is insufficient; a full device reset is required if compromise is suspected, due to the advanced nature of the attacks.
Rapid7 observes initial exploitation of SonicWall zero-days in the wild.
SonicWall releases patches for CVE-2026-15409 and CVE-2026-15410.
CISA adds both vulnerabilities to its KEV catalog.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.