Home/News/SonicWall SMA Zero-Days Exploited Before Public Disclosure
The Hacker News2 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

SonicWall SMA Zero-Days Exploited Before Public Disclosure

SonicWall SMA Zero-Days Exploited Before Public Disclosure

A previously undocumented threat actor, tracked by cybersecurity firm Volexity as UTA0533, exploited SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior to their public disclosure. Volexity's investigation into an incident response case revealed that these vulnerabilities were actively exploited as early as June 22, 2026, before SonicWall was aware of the specific flaws. The exploitation allowed the threat actor to gain root-level access to the affected appliances, indicating a high level of sophistication and intent.

SonicWall confirmed the exploitation in a security advisory released on July 10, 2026, acknowledging that the vulnerabilities were leveraged in the wild. The company stated that the threat actor used a previously unknown method to bypass authentication and gain administrative control. This bypass involved manipulating specific API calls within the SMA 1000 series to execute arbitrary commands on the underlying operating system. The advisory did not specify the exact number of affected customers but urged all users of the SMA 1000 series to apply the available patches immediately.

Following the disclosure, SonicWall released emergency patches and updated firmware for the affected SMA 1000 series appliances. The company recommended that customers perform a full system reset and reconfigure their devices after applying the patches to ensure complete removal of any potential backdoors or persistent threats. Volexity's analysis suggests that UTA0533 may have been using the compromised appliances to conduct further reconnaissance or to pivot into victim networks, though the full scope of the actor's objectives remains under investigation. The incident highlights the critical importance of prompt patching and robust incident response capabilities for organizations relying on VPN infrastructure.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next