SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
Overview
A new threat actor, identified as UTA0533, has been exploiting zero-day vulnerabilities in SonicWall's Secure Mobile Access (SMA) 1000 series VPN appliances before these issues were publicly disclosed. This activity has been tracked since June 22, 2026, and was uncovered during an incident response investigation by cybersecurity firm Volexity. The attackers gained root access to systems, raising serious concerns about the security of organizations using these VPN appliances. This incident is particularly alarming as it highlights the potential risks associated with undisclosed vulnerabilities, which can be exploited by malicious actors before users have a chance to protect themselves. Organizations using SonicWall SMA appliances should be vigilant and prepare for potential impacts from these vulnerabilities.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances
- Action Required: Organizations should apply any available patches from SonicWall and review their security configurations for the SMA 1000 series.
- Timeline: Disclosed on June 22, 2026
Original Article Summary
A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026. Cybersecurity company Volexity is tracking the activity under the moniker UTA0533. The discovery was made following an incident response investigation earlier this
Impact
SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Disclosed on June 22, 2026
Remediation
Organizations should apply any available patches from SonicWall and review their security configurations for the SMA 1000 series.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Zero-day, Vulnerability.