INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

SonicWall SMA Zero-Days Exploit Vulnerability

| 2026-07-20 22:23 CRITICAL MEDIUM EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The SonicWall SMA1000 Secure Mobile Access appliances have been compromised by a threat actor using multiple zero-day exploits, including two previously undisclosed vulnerabilities in an exploit chain that affected the devices. The attackers exploited CVE-2026-15409 and CVE-2026-15410 to establish unauthenticated WebSocket tunnels to services accessible only from the appliance itself, allowing them to execute commands as root and gain full control of the device. Additionally, they installed a custom malware dropper called KNUCKLEBALL under the file name '[IOC HIDDEN • LOGIN REQUIRED]' after obtaining the appliance's product_uuid through exploitation of CVE-2026-15410 command injection vulnerability. The attackers also modified the appliance's nginx configuration to expose an ORANGETAIL webshell remotely and used ROOTRUN, a privilege-escalation tool, to execute commands as root. This threat actor was observed using multiple zero-day exploits, including Sou5 (agent_wp8.jar) and ORANGETAIL (agent_wp9.jar), designed for SonicWall SMA1000 appliances.
Technical Mitigations AI-generated
* Implement a secure patching strategy for all vulnerable devices, including regular updates and patches to address known vulnerabilities before they can be exploited. * Conduct thorough vulnerability scanning and penetration testing on new or untested systems to identify potential zero-day exploits before they can be used against them. * Educate users about the importance of keeping software up-to-date and patched, as well as the risks associated with using outdated or unpatched devices. * Implement a robust incident response plan that includes procedures for responding to zero-day attacks, including containment, eradication, recovery, and post-incident activities.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

sy•••••.execremovehotfix
ct•••••.log
li•••••.sh
co•••••.json
er•••••.jsp
er•••••.jsp
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-56155CVE-2026-56155 CVE-2026-15409CVE-2026-15409 CVE-2025-23006CVE-2025-23006 CVE-2026-15410CVE-2026-15410 CVE-2026-56164CVE-2026-56164
Target & Sectors
NORTH_AMERICA NORTH_AMERICA governmentgovernment
Incident Timeline
‎late 2021
Seventeen defects affecting SonicWall products were discovered and added to the US-CISA known exploited vulnerabilities catalog in late 2021.
‎June 22, 2026
Threat actors used an ELF executable to write a malicious program on June 22, 2026.
organisation SonicWall Secure Mobile Access
organisation SMA
general_metric 1000 series
general_metric 1 Appliance
‎June 22
Rapid7 researchers disclosed both vulnerabilities on June 22.
organisation CyberScoop
‎July 2, 2026
Threat actors exploited a zero-day vulnerability in the SonicWall SMA Zero-Day Exploit Vulnerability.
‎2026/07/13
Threat actors exploited two previously undisclosed vulnerabilities in SonicWall SMA1000 Secure Mobile Access appliances.
organisation Secure Mobile Access
‎July 14, 2026
Threat actors exploited a zero-day vulnerability in the SonicWall SMA1000 appliances.
‎July 14
Threat actors exploited a zero-day vulnerability in SonicWall's SMA 1000 Series appliances to gain unauthorized access and connect to ransomware.
vulnerability CVE-2026-15409
vulnerability CVE-2026-15410
tactic Ransomware
tactic T1588.006 - Vulnerabilities
attribution Connection to Inc Ransomware
attribution Known Exploited
attribution KEV
organisation CVE-2026
general_metric 1000 series
‎Jul 15, 2026
Threat actors exploited a previously unknown vulnerability in the SonicWall SMA Zero-Day Exploit.
‎July 15
Threat actors exploited a zero-day vulnerability in the SonicWall SMA Zero-Day Exploit Vulnerability.
‎July 17, 2026
SonicWall's SMA Zero-Day Exploit Vulnerability was identified and publicly disclosed by SecurityAffairs, prompting the US Cybersecurity and Infrastructure Security Agency (CISA) to add it to its Known Exploited Vulnerabilities catalog.
vulnerability CVE-2026-56155
attribution SecurityAffairs
tactic T1588.006 - Vulnerabilities
attribution Known Exploited
attribution KEV
attribution FCEB
attribution Federal Civilian Executive Branch
general_metric 26 Binding Operational Directive
‎2026/07/20
SonicWall released patches for the SMA1000 Appliance Management Console vulnerability.
organisation Secure Mobile Access
organisation SonicWall
organisation SMA
organisation Microsoft
organisation Vulnerability / Enterprise Security
organisation CVE-2026
organisation WebSocket
organisation CVE-2026-15409
organisation the Appliance Management Console's '
organisation RPC
organisation Gold Eagle Clearinghouse Targets
organisation CVSS
organisation Appliance Management Console
organisation AMC
organisation UI
organisation the Appliance Management Console
organisation the SMA1000 Appliance Management Console
infrastructure 12.4.3-03453
infrastructure 12.5.0-02835
organisation API
organisation PoC
organisation SonicWall SMA 1000
infrastructure 1000 devices
organisation KNUCKLEBALL
organisation JAR
organisation Volexity
organisation SonicWall SMA VPN
organisation ORANGETAIL
organisation ROOTRUN
organisation EDR
organisation NGINX
organisation SonicWall SMA
organisation SecurityAffairs
organisation Cybersecurity company Volexity
organisation UUID
organisation SMA Connect
organisation bmID=-3389
financial 40 ransomware attacks
organisation CVE-2025
organisation the Common Vulnerability Scoring System
organisation Ivanti
organisation Fortinet
organisation Deroche
organisation Counter Threat Unit
organisation the SMA1000 Appliance Work Place
infrastructure 12.4.3-03245
infrastructure 12.4.3-03387
infrastructure 12.4.3-03434
infrastructure 12.5.0-02283
infrastructure 12.5.0-02624
infrastructure 12.5.0-02800
organisation IOC
organisation SonicWall Firewall
organisation BleepingComputer
‎July 2026
Threat actors exploited a zero-day vulnerability in SonicWall SMA Zero-Day Exploit Vulnerability.
organisation KEV
‎July 28, 2026
Threat actors used a zero-day exploit in the SonicWall SMA Zero-Day Vulnerability to target users.
vulnerability CVE-2026-56155
attribution SecurityAffairs
Tactical Metrics
Metrics
infrastructure
‎12.4.3-03453
Software Version
Metrics
infrastructure
‎12.5.0-02835
Software Version
Metrics
infrastructure
1,000
Devices
Metrics
infrastructure
‎Ivanti
Affected Product
Metrics
financial
40
Ransomware Attacks
Metrics
infrastructure
‎12.4.3-03245
Software Version
Metrics
infrastructure
‎12.4.3-03387
Software Version
Metrics
infrastructure
‎12.4.3-03434
Software Version
Metrics
infrastructure
‎12.5.0-02283
Software Version
Metrics
infrastructure
‎12.5.0-02624
Software Version
Metrics
infrastructure
‎12.5.0-02800
Software Version