CRITICAL ⚡ MUST-KNOW
SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
A previously undocumented threat actor, tracked by Volexity as UTA0533, exploited zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances before they were publicly disclosed. Exploitation has been observed since at least June 22, 2026. The flaws allowed attackers to gain root access on affected appliances. Volexity identified the activity during an incident response investigation. Organizations running SonicWall SMA 1000 series appliances should apply available patches immediately and review appliance logs for signs of compromise.