A Previously Unknown Hacking Group Rooted SonicWall VPN Appliances for a Month Before Anyone Noticed
A previously undocumented threat actor spent nearly a month running zero-day exploits against SonicWall's SMA 1000 series VPN appliances before either vulnerability was ever publicly disclosed, according to incident-response findings published by security firm Volexity. The group, which Volexity tracks as UTA0533, chained the two flaws to gain full root access on the devices that organizations rely on to secure remote employee access to their networks — turning the gateway meant to keep attackers out into the attacker's own entry point.
The first flaw, CVE-2026-15409, carries the maximum possible severity score of 10.0 and lets a remote attacker with no credentials at all open a hidden tunnel into services on the appliance that were never meant to be reachable from the outside. The second, CVE-2026-15410, is a path-traversal bug that, once inside, lets the attacker escalate straight to root. Chained together, the two flaws gave UTA0533 complete control of the appliance starting as early as June 22 — three weeks before SonicWall issued a patch on July 14.
With root access, Volexity found the attacker could pull stored and cached credentials directly off the device, intercept authentication traffic passing through it, and capture session data — all without leaving the kind of trace a compromised employee laptop or server normally would. Separately, researchers at Rapid7 identified a threat actor connected to the Inc ransomware group actively exploiting the same two vulnerabilities against other organizations to gain an initial foothold before attempting to move deeper into corporate networks.
Because a VPN appliance sits at the edge of a network and is trusted by design, a compromised one can quietly authenticate as legitimate remote-access traffic while an attacker moves further inside. SonicWall has released hotfixed firmware for the affected SMA 1000 platform versions and says standard SonicWall firewalls and its separate SMA 100 series are not affected. The company is urging any organization running the vulnerable appliances not just to patch, but to check for signs the device was already compromised before doing so — since installing a fix does nothing to remove an attacker who got in weeks earlier.