SonicWall SMA1000 Zero-Days (CVE-2026-15409, CVE-2026-15410) Chained in Active Attacks, Assessed Ransomware Precursor — Threadlinqs Intelligence
As of 2026-07-23, SonicWall SMA1000 Zero-Days (CVE-2026-15409, CVE-2026-15410) Chained in Active Attacks, Assessed Ransomware Precursor is a critical-severity vulnerability threat attributed to UTA0533 (China (suspected, moderate confidence)), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 51 indicators of compromise.
Threat ID: TL-2026-1462 · Severity: CRITICAL · CVSS: 10 · Status: ACTIVE · Category: VULNERABILITY
Updated: 2026-07-23 · 2 updates · revalidated 2× · latest source
Attribution: UTA0533 · China (suspected, moderate confidence) · ESPIONAGE
Rapid7's MDR team discovered attackers chaining an unauthenticated CVSS 10.0 SSRF (CVE-2026-15409) with a post-authentication code injection flaw (CVE-2026-15410) in SonicWall SMA1000 secure remote
SonicWall SMA1000-series secure mobile access appliances (models SMA6210, SMA7210, SMA8200v) were found to contain two chainable zero-day vulnerabilities that together provide a fully remote, unauthenticated path to root-level operating system command execution. CVE-2026-15409 is a CWE-918 server-side request forgery (SSRF) in the SMA1000 WorkPlace web interface (port 443): an unauthenticated remote attacker can abuse the /wsproxy endpoint, which builds websocket-based TCP tunnels from attacker-supplied host/port parameters, to reach localhost-only internal services that are otherwise unreachable from the network. Rapid7 observed attackers using this SSRF to pivot to the ctrl-service application listening on localhost:8188, and to a hardcoded-cookie-authenticated Erlang process on localhost:1050 that provided initial code execution as the low-privileged couchdb user (UID 1010).
CVE-2026-15410 is a CWE-94 code injection vulnerability in the Appliance Management Console (AMC) / ctrl-service's remove_hotfix workflow. The workflow fails to validate hotfix filenames supplied to it, allowing path traversal sequences (e.g. "../../../../../../tmp/") to be smuggled through and executed as arbitrary OS commands running as root. SonicWall's own advisory (SNWLID-2026-0008) scopes CVE-2026-15410 as requiring high privileges (a remote authenticated administrator), giving it a standalone CVSS v3.1 score of 7.2 (AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H); however, because CVE-2026-15409's SSRF grants an unauthenticated actor a network path directly to the same internal ctrl-service listener that CVE-2026-15410 targets, security researchers (Tenable, Rapid7) assess the pair combine into a single unauthenticated, fully remote root-RCE chain — consistent with the CVSS 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) rating assigned to CVE-2026-15409 itself.
Rapid7's MDR team first observed exploitation in the wild on June 22, 2026 (per reporting to CyberScoop), with a wider wave of targeted, internet-facing exploitation flagged around July 9, 2026. Post-compromise activity observed by Rapid7 included reconnaissance of the exposed appliance, harvesting of stored credentials, session databases, and TOTP MFA seed configuration from the appliance, and subsequent lateral movement — attackers authenticated directly to Active Directory domain controllers from the compromised appliance's IP address without ever establishing a legitimate VPN session, effectively using the SMA1000 as an unmonitored backdoor into the internal network. Overlapping TTPs across observed intrusions point to a single threat actor or a small cluster of closely coordinated actors, though SonicWall and Rapid7 have not published a named-group attribution. Rapid7 assessed the intrusions as ransomware-motivated based on post-exploitation behavior, but reported that in the cases it observed, MDR response actions prevented the actors from completing data exfiltration or deploying ransomware/encryption. A prior source URL referencing an "INC ransomware" attribution for this campaign (darkreading.com) returned HTTP 403 and could not be corroborated via search; no ransomware group name is asserted in this record.
SonicWall published advisory SNWLID-2026-0008 on July 14, 2026, confirming multiple customer incidents of active exploitation and releasing hotfixed firmware (12.4.3-03453 and 12.5.0-02835) with no interim workaround available. CISA added both CVEs to the Known Exploited Vulnerabilities (KEV) catalog on July 15, 2026, with a Federal Civilian Executive Branch remediation deadline of July 17, 2026 under Binding Operational Directive 22-01. Given the confirmed compromise activity, SonicWall's guidance for affected organizations goes beyond patching: full forensic log review, re-imaging or redeployment of appliances where compromise indicators are found, rotation of all user and administrator credentials, and regeneration of TOTP MFA seeds are all recommended, since simply patching a compromi
Weaknesses (CWE)
CWE-918, CWE-94, CWE-22, CWE-78
Target sectors: government administration, finance, health, technology, critical-infrastructure, professional-services
Target regions: North America, Europe, Global
Update History
- 2026-07-23 — SonicWall SMA1000 Unauthenticated SSRF-to-RCE Chain (CVE-2026-15409, CVE-2026-15410) — UTA0533 Exploits WorkPlace WebSocket Proxy, Deploys KNUCKLEBALL/ORANGETAIL/Suo5/ROOTRUN, Actively Exploited Since June 2026, CISA KEV: What changed Attribution firmed up: nation-state moved from Unknown to China (suspected, moderate confidence) and attribution_confidence escalated LOW → MEDIUM, based on Volexity's 'Proxying to Compromise' report attributing the campaign to
- 2026-07-20 — SonicWall SMA1000 Zero-Days (CVE-2026-15409, CVE-2026-15410) Chained by UTA0533 to Deploy KNUCKLEBALL, ORANGETAIL Webshell, and Suo5 Proxy: What changed Attribution moved from Unattributed/financially-motivated (Rapid7 MDR, ransomware-precursor assessment) to named intrusion set UTA0533 with an espionage/state-sponsored assessment (Volexity), based on distinct custom tooling an
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 51 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-15409, CVE-2026-15410, T1190, T1059, T1203, T1505, T1068, T1211, T1556, T1070, T1552, T1111