SonicWall SMA1000 flaws exploited as zero-days to push custom malware

Zero-Day Attacks Exploit SonicWall SMA1000 Flaws, Push Custom Malware

A highly sophisticated threat actor has been exploiting two previously undisclosed vulnerabilities in SonicWall’s SMA1000 Secure Mobile Access appliances for weeks, installing custom malware on vulnerable VPN devices. The attacks took place long before the vulnerabilities were publicly disclosed by SonicWall last week, and experts warn that many organizations may still be unaware of the risk.

The flaws, tracked as CVE-2026-15409 and CVE-2026-15410, allow attackers to install malicious code on SMA1000 appliances, which are used to provide secure remote access to corporate networks. The vulnerabilities affect SMA1000 models 6210, 7210, and 8200v, and SonicWall has released patches in versions 12.4.3-03453 and 12.5.0-02835.

Incident response firm Volexity, which assisted SonicWall in investigating the attacks, has published a detailed report on the exploitation chain used by the threat actor. According to Volexity, the attackers first exploited the SSRF vulnerability (CVE-2026-15409) to establish unauthenticated WebSocket tunnels to internal services, including CouchDB and the VPN device’s management service.

Using this access, the attackers queried CouchDB to obtain a unique identifier required for the second stage of the attack. They then exploited the command injection vulnerability (CVE-2026-15410) through the Appliance Management Console’s RPC method, allowing them to execute commands as root and take full control of the appliance.

With root access, the threat actor installed a custom malware dropper called KNUCKLEBALL, which deployed two Java-based malware families: Sou5 and ORANGETAIL. These malware families allow attackers to maintain covert access to internal resources and dynamically execute malicious code within an HTTP session.

Experts warn that this campaign demonstrates significant technical sophistication, but the threat actor’s success in spreading into victims’ internal networks is limited. This highlights the importance of patching vulnerabilities promptly and regularly monitoring network activity for signs of malicious behavior.

SonicWall customers are urged to install the latest patches immediately to protect their appliances from these zero-day attacks. Organizations without SonicWall appliances should also review their security posture and ensure that they have a robust incident response plan in place to detect and respond to similar threats.

The takeaway here is clear: no matter how advanced your security measures, attackers will always find ways to exploit vulnerabilities if you don’t stay ahead of the curve. Regularly patching and updating your systems is crucial, but it’s equally important to continuously monitor network activity for signs of malicious behavior. Don’t wait until it’s too late – test every layer of your security today.


Source: Bleeping Computer — 2026-07-20