PT-2026-61591 · Undefined · Undefined

CVE-2026-154010

·

Published

2026-07-20

·

Updated

2026-07-20

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
#threatreport #LowCompleteness Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation | 17-07-2026 Source: https://t.co/LPIxpEauiy Key details below ↓
🧑‍💻Actors/Campaigns: Uta0533
💀Threats: Xzfind tool, Rootrun tool, Knuckleball, Suo5 tool, Behinder, Orangetail, 🎯Victims: Vpn appliances, Network infrastructure, Organizations
🔓CVEs: CVE-2026-15410 [Vulners]
  • CVSS V3.1: 7.2,
  • Vulners: Exploitation: True
CVE-2026-15409 [Vulners]
  • CVSS V3.1: 10.0,
  • Vulners: Exploitation: True
CVE-2026-154010 [Vulners]
  • CVSS V3.1: Unknown,
  • Vulners: Exploitation: Unknown
🤖LLM extracted TTPs:` T1037.004, T1040, T1055, T1057, T1059.004, T1059.006, T1068, T1070.004, T1090.001, T1105, ...
🧨IOCs:
  • File: 10
  • IP: 8
  • Hash: 4
💽Software: Volexity Volcano, nginx, Unix
🔢Algorithms: base64, md5, sha256, aes-128-ecb, aes, sha1
🔠Functions: Volexity, setuid, getMethod
📜Programming Languages: java, python
💻Platforms: x64
#threatreport: In July 2026, Volexity conducted an incident response investigation for a compromise involving SonicWall Secure Mobile Access (SMA) VPN appliances. The investigation revealed that a threat actor, tracked by Volexity as UTA0533, exploited a chain of multiple zero-day vulnerabilities to gain unauthorized access to the devices. Initial signs of the compromise were identified through unusual authentication and lateral movement attempts observed from the appliances. Using administrative SSH access to the devices, Volexity analyzed system memory and logs, confirming the presence of malware and exploitation techniques.
The first appliance compromised on June 22, 2026, exhibited malicious modifications including a setuid binary named "rootrun," which allowed non-privileged users to execute commands as root. Additionally, Volexity identified a malware script dubbed "KNUCKLEBALL," which embedded two Java archive (JAR) files: an HTTP proxy-forwarding tool called Suo5 and a webshell referred to as ORANGETAIL. These implants facilitated external access via specific malicious URIs linked to the NGINX configuration, with access filtered by user-agent strings. Notably, the exploitation chain included a local privilege escalation exploit designated CVE-2026-15410.
In contrast, the second compromised appliance exhibited fewer signs of exploitation but shared the same NGINX configuration modifications. The appliance had been rebooted, potentially clearing transient backdoors, but still demonstrated evidence of attempts to capture unencrypted LDAP traffic using tcpdump.
Indicators of compromise (IOCs) included unexpected modifications in system paths, unauthorized setuid binaries, and unexpected routes in the NGINX configuration. Volexity underscored the importance of monitoring SonicWall SMA appliances for unusual files in temporary directories and unexpected connections, particularly alerting to any unauthorized authentication attempts from the appliances to other network systems.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-154010

Affected Products

Undefined