SonicWall SMA1000 Flaws Exposed as Zero-Days to Install Custom Malware
A serious security breach has come to light involving SonicWall’s SMA1000 Secure Mobile Access appliances. Two previously undisclosed vulnerabilities were exploited by threat actors for weeks, allowing them to install custom malware on vulnerable VPN devices. The flaws, tracked as CVE-2026-15409 and CVE-2026-15410, affect SMA1000 6210, 7210, and 8200v appliances.
The attacks began in early June, with the threat actors exploiting the vulnerabilities in a zero-day attack chain. This means that the exploiters were using previously unknown methods to gain access to the devices. The attackers used the flaws to install custom malware on compromised SMA1000 appliances, allowing them to maintain covert access to internal resources.
According to a report by incident response firm Volexity, which assisted SonicWall in investigating the attacks, the threat actors used multiple zero-day exploits and malware designed specifically for SonicWall SMA VPN appliances. The attackers first exploited CVE-2026-15409 to abuse the SMA1000’s ‘wsproxy’ endpoint, allowing them to establish unauthenticated WebSocket tunnels to internal services.
Using this access, the attackers queried CouchDB to obtain the appliance’s product_uuid, a value required to complete the second stage of the attack. The attackers then exploited the CVE-2026-15410 command injection vulnerability through the Appliance Management Console’s ‘sysCtrl.execRemoveHotfix’ RPC method, allowing them to execute commands as root and take full control of the appliance.
With root access, the threat actors installed a custom malware dropper that Volexity calls KNUCKLEBALL under the file name ‘deploy_new.py’. This malware is used to deploy two Java-based malware families: Sou5 (agent_wp8.jar) and ORANGETAIL (agent_wp9.jar). These malware families are designed for SonicWall SMA1000 appliances, with Sou5 functioning as a reverse proxy allowing attackers to tunnel traffic through the compromised appliance, and ORANGETAIL being a custom Java webshell that allows attackers to send encrypted Java payloads.
The researchers also found that the attackers modified the appliance’s nginx configuration to expose the ORANGETAIL webshell remotely and installed ROOTRUN, a privilege-escalation tool. While the campaign and malware showed significant technical sophistication, the threat actor was less successful at spreading into victims’ internal networks.
This incident highlights the importance of patching vulnerabilities as soon as possible. SonicWall released patches in versions 12.4.3-03453 and 12.5.0-02835, urging customers to install the updates immediately. It’s essential for organizations using SonicWall SMA1000 appliances to review their security measures and ensure they are up-to-date with the latest patches.
In conclusion, this incident serves as a reminder that security teams must stay vigilant and proactive in protecting against emerging threats. By regularly testing and updating their defenses, organizations can reduce the risk of falling victim to similar attacks.
Source: Bleeping Computer — 2026-07-20