SonicWall has patched two zero-day vulnerabilities in its SMA1000 series appliances after security researchers caught them being actively exploited since at least June 22. This is a separate incident from the SonicWall SSL-VPN flaw that led to the 70-plus bank and credit union breach reported in June, a reminder that enterprise VPN appliances have had a genuinely rough 2026.

The vulnerabilities

CVE-2026-15409 is a critical server-side request forgery flaw (CVSS 10.0, the maximum possible score) in the SMA1000 Appliance Work Place interface, letting a remote, unauthenticated attacker force the appliance to make requests to locations of the attacker’s choosing. CVE-2026-15410 is a high-severity (CVSS 7.2) post-authentication code injection flaw in the Management Console, letting an authenticated administrator account execute arbitrary operating system commands. Together, chained, they gave attackers a path from zero access to full device compromise.

The affected hardware is SonicWall’s SMA6210, SMA7210, and SMA8200v appliances, the SMA1000 series used by businesses to provide secure remote access, effectively enterprise VPN gateways.

How attackers used them

Researchers at Rapid7 and Volexity, who tracked the exploitation to a threat actor designated UTA0533, found the two flaws were exploited in tandem for stealthy initial access. Once inside, the attackers extracted high-value data: stored credentials, active session databases, and TOTP multi-factor authentication seed configurations. Harvesting MFA seeds is the detail that makes this worse than a typical credential theft, it lets an attacker generate valid two-factor codes and maintain long-term access even after passwords are reset, unless the MFA seeds themselves are also rotated.

Timeline

Exploitation began as early as June 22, 2026, according to Volexity’s analysis. SonicWall alerted customers directly ahead of public disclosure, advising them to contact support for hotfixes (versions 12.4.3-03453 and 12.5.0-02835) before the patches were posted publicly on July 14. CISA added both CVEs to its Known Exploited Vulnerabilities catalog and ordered US federal civilian agencies to remediate by July 17, 2026, and to investigate whether their own appliances had already been compromised.

SSRF and code injection, in plain terms

Server-side request forgery means tricking a server into making network requests on the attacker’s behalf, from inside the network perimeter the appliance normally protects, effectively using the VPN gateway itself as a pivot point once the SSRF is triggered. Code injection means smuggling operating system commands into a field the appliance’s management interface wasn’t designed to execute directly, turning administrative access into full command execution. Neither vulnerability class is new or exotic; what made this dangerous was chaining an unauthenticated SSRF with a post-auth injection flaw, using the first bug to reach a position where the second one became exploitable without ever needing valid credentials to start.

Who is UTA0533

UTA0533 is the working designation Volexity assigned to the threat actor behind this campaign; it’s not a name tied to a previously well-known group, which is typical for a newly identified cluster of activity rather than a rebrand of an established gang. The focus on credential and MFA-seed harvesting rather than immediate ransomware deployment suggests an actor prioritizing long-term, stealthy access over a fast payout, a pattern security researchers increasingly associate with espionage-motivated intrusions rather than purely financial ones, though attribution at this stage remains provisional.

Why this keeps happening to SonicWall specifically

This is the second major SonicWall VPN incident to make headlines in as many months. In June, a separate SSL-VPN vulnerability allowing MFA bypass was exploited by the Akira ransomware group to breach Marquis Software Solutions, a vendor serving community banks and credit unions, exposing data at more than 70 institutions. That flaw and this one are different vulnerabilities in different product lines, but the pattern is the same: enterprise VPN gateways sit at the network edge by design, making them a uniquely valuable target, and a uniquely damaging one to get wrong.

Enterprise SSL-VPN appliances broadly have had a difficult stretch; Fortinet’s FortiOS SSL-VPN also saw active exploitation of a years-old flaw earlier this year. If your organization runs any internet-facing VPN gateway, treat patch cycles for that specific class of device as higher priority than general software updates, given how consistently they’ve been targeted in 2026.

Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.

What this means if you use a consumer VPN

If you’re using a consumer VPN service like NordVPN, ExpressVPN, or Surfshark for personal privacy or streaming, this specific incident doesn’t touch you directly, SMA1000 appliances are enterprise remote-access gateways, not consumer VPN apps, and they run on fundamentally different infrastructure. The relevant takeaway is broader: VPN software of any kind is only as secure as its maintainer’s patch discipline, and providers with a strong track record of fast, transparent disclosure (the kind covered in independent no-logs audits and transparency reports) are the ones worth trusting with your traffic.

A pattern across 2026, not an isolated event

Zoom out and this is the third or fourth major enterprise VPN gateway incident of the year across different vendors: the SonicWall SSL-VPN flaw tied to the Marquis Software bank breach in June, Fortinet’s FortiOS SSL-VPN seeing renewed exploitation of a years-old authentication bypass, and now this SMA1000 zero-day pair. None of these are consumer-facing products, but they share a root cause worth naming: internet-facing VPN gateways are high-value, high-visibility targets, and the appliances running them don’t always get patched as quickly as the software running on end-user devices, in part because taking an enterprise gateway offline for an update has real business cost that a phone or laptop update doesn’t.

What SonicWall SMA1000 customers should do now

Apply the hotfixes immediately if you haven’t already; both CVEs are confirmed under active exploitation, not theoretical. Rotate credentials and, critically, MFA seed configurations for accounts on affected appliances, since seed theft survives a simple password reset. Review session logs for the period since June 22 for signs of the tandem exploitation pattern researchers described. If your organization was affected, Rapid7 and SonicWall’s own advisory both include indicators of compromise to check against.

What to watch next

CISA’s Known Exploited Vulnerabilities catalog is the fastest public signal for whether a flaw like this is being actively weaponized at scale versus contained to a narrow, targeted campaign; both CVEs are already listed. Expect follow-up disclosures if UTA0533’s activity is later tied to broader victim lists, that’s the typical pattern once initial reporting draws more researcher attention to a campaign.

Our verdict

Two critical, actively-exploited zero-days in enterprise VPN hardware, patched but only after roughly three weeks of exploitation in the wild. If you administer SonicWall SMA1000 appliances, patch and rotate MFA seeds now, this is not a theoretical risk. For personal VPN users, the incident is a reminder that enterprise VPN gateways and consumer VPN apps are different products with different risk profiles, don't let headlines about one shake confidence in the other without cause.

For more on enterprise VPN security incidents this year, see our coverage of the SonicWall bank breach and our broader look at enterprise SSL-VPN breaches in 2026.