🔴 Critical | Source: The Hacker News
A previously unknown threat actor, tracked as UTA0533, exploited zero-day vulnerabilities in SonicWall SMA 1000 series VPN appliances to gain root-level access before the flaws were publicly disclosed. Exploitation is believed to have begun as early as 22 June 2026, discovered during an incident response investigation by Volexity. This is significant because VPN appliances sit at the network perimeter and root access means full device compromise, potentially exposing internal corporate networks.
Security Architect’s Take: If you operate SonicWall SMA 1000 series appliances, apply the relevant patches immediately and treat any unpatched devices as potentially compromised — initiate forensic review of logs from 22 June 2026 onwards. Consider temporarily restricting or replacing VPN access with zero-trust alternatives whilst remediation is under way.
Original advisory: SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access