Two critical vulnerabilities in SonicWall SMA1000 appliances have been under exploitation as zero-days since late June, according to a report released Friday by Volexity, a Washington, D.C.–based cybersecurity firm.
A threat actor tracked as UTA0533 is linked to the threat activity that began June 22, about three weeks before SonicWall’s July 14 hotfix release for two critical vulnerabilities in its SMA1000 remote access appliances.
The exploit is linked to a server-side request forgery vulnerability in the SMA1000 Appliance Work Place Interface, tracked as CVE-2026-15409, The vulnerability, which allows an attacker to make requests to an unintended location, has a severity score of 10.
A code-injection flaw in the SMA1000 Appliance Management Console, tracked as CVE-2026-15410, could enable an authenticated attacker to execute arbitrary commands. The code-injection flaw is chained to the server-side request forgery vulnerability during the attack sequence.
According to Volexity, the threat actor used Knuckleball malware to drop SMA-specific malware implants. The implants contained a web shell that researchers call Orangetail.
Researchers at Rapid7 said successful compromise of these vulnerabilities can leave organizations highly vulnerable to attack.
“The potential risk to customer environments is severe, as successful exploitation of this chain grants unauthenticated attackers remote code execution privileges as root,” Douglas McKee, director of vulnerability intelligence at Rapid7, told Cybersecurity Dive. “Once inside, threat actors systematically harvest local credentials, active session databases, and multifactor authentication (MFA) seeds to maintain long-term persistence.”
McKee said initial threat activity was linked to various IP addresses assigned to F.N.S. Holdings Ltd., a VPN hosting provider. However, more recently, INC ransomware has been linked to the exploitation. INC ransomware is a ransomware-as-a-service syndicate that uses double extortion tactics.
Researchers at Huntress confirmed that seven customers have been impacted by the exploitation of the SonicWall vulnerabilities. The researchers said the “two disparate sets of attackers” have been linked to the threat activity.
The threat actors attempted to steal credentials using Impacket’s Secrets Dump, which is a Python tool used to extract Windows credentials. The hackers also used DCSync, which can take credentials from an Active Directory environment.
Apply remediations
SonicWall said its incident response experts have responded to multiple cases related to the vulnerabilities and is urging customers to upgrade to the hotfix release as soon as possible.
The company said the vulnerabilities do not impact the SSL-VPN running on SonicWall firewalls or SMA100 series products.
The Cybersecurity and Infrastructure Security Agency added the two flaws to its Known Exploited Vulnerabilities catalog on July 14.