| CVE | Vulnerability type | Main risk |
|---|---|---|
| CVE-2026-15409 | Server-side request forgery in the SMA 1000 Work Place interface | Remote unauthenticated attacker may force the appliance to send unintended requests |
| CVE-2026-15410 | Code injection / RCE in the SMA 1000 Appliance Management Console | Remote authenticated administrator may execute arbitrary OS commands under specific conditions |
SonicWall SMA Flaws Lead to KNUCKLEBALL Malware
SonicWall SMA 1000 appliances were compromised in a zero-day campaign involving custom malware, root-level access, credential gathering, and attempts to move deeper into victim environments. One key malware component was KNUCKLEBALL, a Python-based tool observed on compromised SonicWall Secure Mobile Access appliances.
The campaign abused two SonicWall SMA 1000 zero-day vulnerabilities, CVE-2026-15409 and CVE-2026-15410. SonicWall published hotfix guidance on July 14, 2026, and confirmed active exploitation, while CISA added both flaws to its Known Exploited Vulnerabilities catalog.
What Happened in the KNUCKLEBALL Campaign?
Researchers investigated compromised SonicWall SMA appliances in early July 2026 and linked the activity to a threat actor they track as UTA0533. The investigation also determined that the exploitation began on June 22, 2026.
The attacker did more than simply exploit an edge device. Researchers discovered root-level access, SMA-specific malware deployment, credential gathering, traffic capture, and attempts to pivot from compromised appliances to internal systems.

Exploit chain to deploy KNUCKLEBALL (Volexity)
SMA appliances often sit close to authentication, remote access, and internal routing paths. Patching closes the known vulnerability path if an attacker breaches that layer, but it might not eliminate malware, credentials that have been stolen, or indications of lateral movement.
Which SonicWall SMA Vulnerabilities Are Involved?
SonicWall’s advisory covers two vulnerabilities affecting the SMA 1000 Series. The company confirmed that the vulnerabilities were being actively exploited in the wild and urged affected customers to install the latest hotfix release, perform forensic analysis, and check for indicators of compromise.
SonicWall notes this campaign is unrelated to vulnerabilities affecting other SonicWall product lines. The affected product line is the SMA 1000 Series, not SonicWall firewall SSL VPN functionality or the SMA 100 Series.
What Is CVE-2026-15409?
CVE-2026-15409 (CVSS 10.0) is a server-side request forgery vulnerability in the SMA 1000 Appliance Work Place interface. Essentially, it allows an attacker to use the exposed appliance as a relay. Instead of connecting directly to local-only services, the attacker may force the appliance to do so on their behalf.
Volexity reported that attackers abused the /wsproxy path to create unauthenticated WebSocket tunnels to local-only services on the appliance. That made CVE-2026-15409 a key first step in the observed exploitation chain.

Details of CVE-2026-15409 (SOCRadar Vulnerability Intelligence)
What Is CVE-2026-15410?
CVE-2026-15410 (CVSS 7.2) is a post-authentication code injection vulnerability in the SMA 1000 Appliance Management Console (AMC). This vulnerability is not classified as unauthenticated by itself; CVE-2026-15409 exposed internal appliance services that enabled the next stage of the attack chain.
Researchers described abuse of the hotfix removal workflow through the sysCtrl.execRemoveHotfix RPC method. It is also noted that attackers used this path to execute commands as root and take control of the appliance.

Details of CVE-2026-15410 (SOCRadar Vulnerability Intelligence)
How Were the SonicWall Zero-Days Chained?
At a high level, the observed exploitation chain worked like this:
- The attacker reached the exposed SMA Work Place interface.
- They abused /wsproxy behavior to access localhost-only services.
- They queried internal services and obtained data needed for the next stage.
- They abused the hotfix removal path to execute attacker-controlled content.
- They gained root-level access and deployed SMA-specific malware.
This chain shows why exposed secure access appliances are high-value targets. They sit close to authentication and remote access paths, which can turn an edge compromise into a broader incident.
What Malware Was Deployed?
The investigation identified several malware components and tools on compromised SonicWall SMA appliances, including KNUCKLEBALL, a Python script named deploy_new.py that deployed SMA-specific Java implants.
Those implants included ORANGETAIL, a custom Java webshell, and a modified Suo5/Sou5-style proxy payload used for remote access and traffic tunneling through the compromised appliance. Volexity also documented ROOTRUN, a Linux ELF utility named xzfind that enabled commands to run with root privileges.
| Malware / tool | File / form | Description |
|---|---|---|
| KNUCKLEBALL | deploy_new.py | Python script used to deploy SMA-specific Java implants |
| ROOTRUN | xzfind | Linux ELF utility used to run commands with root privileges |
| ORANGETAIL | Java webshell | Custom webshell used inside the SMA application environment |
| Modified Suo5/Sou5 proxy | Java payload / proxy tool | Proxying and traffic tunneling through the compromised appliance |
Together, these tools helped the attacker maintain access, interact with compromised devices, and route traffic through SonicWall SMA appliances.
What Did Attackers Do After Compromise?
After gaining root access, attackers attempted to use compromised SMA appliances as internal footholds. Observed activity involved credential gathering, traffic capture, and pivoting attempts from the appliance toward internal systems.
This matters because an SMA appliance may process authentication traffic, connect to directory services, or sit near sensitive internal access paths. Confirmed compromise should be treated as a full appliance breach, not just a patching issue.
Which SonicWall SMA Versions Are Affected?
SonicWall lists affected SMA 1000 Series appliances including 6210, 7210, 8200v, and CMS across all hypervisors. The affected firmware versions are in the 12.4.3 and 12.5.0 branches.
| Affected product | Affected versions | Fixed versions |
|---|---|---|
| SMA 1000 Series: 6210, 7210, 8200v, and CMS | 12.4.3-03245, 12.4.3-03387, 12.4.3-03434 | 12.4.3-03453 or later |
| SMA 1000 Series: 6210, 7210, 8200v, and CMS | 12.5.0-02283, 12.5.0-02624, 12.5.0-02800 | 12.5.0-02835 or later |
Security teams should verify the installed hotfix version directly on each appliance rather than relying only on asset records.
Are CVE-2026-15409 and CVE-2026-15410 in CISA KEV?
Yes. CISA added both vulnerabilities to the Known Exploited Vulnerabilities (KEV) catalog on July 14, 2026. CISA’s entries listed the remediation due date as July 17, 2026 for both CVEs. For federal civilian agencies and organizations that follow KEV-based remediation programs, the short deadline reflects the urgency of the case. Active exploitation, internet-facing appliances, and post-compromise malware make delayed remediation risky.
What Should Security Teams Do Now?
1. Apply Hotfixes and Verify Recovery
Organizations running affected SMA 1000 firmware should upgrade to:
- 12.4.3-03453 or later
- 12.5.0-02835 or later
SonicWall urges customers to install the latest hotfix through MySonicWall and perform forensic analysis to determine whether indicators of compromise are present.
Still, patching does not reverse prior compromise. If indicators are found, SonicWall recommends reimaging hardware appliances or redeploying virtual appliances, changing user and administrator passwords, and resetting TOTP tokens.
2. Prioritize Internet-Facing SMA Appliances
Security teams should prioritize any SMA 1000 appliance reachable from the internet or broad internal network segments.
Review:
- Exposed SMA Work Place interfaces
- Installed hotfix versions
- Unexpected files in /tmp or /var/tmp
- Suspicious /wsproxy activity
- Unexpected routes in /var/lib/unit/conf.json
- Authentication attempts from appliance IP addresses to internal systems
3. Scope Credential and Lateral Movement Risk
Because attackers obtained root access in observed incidents, teams should assume the appliance may have exposed more than its own configuration.
Useful follow-up checks include:
- Directory service authentication from SMA appliance IPs
- Unusual LDAP or authentication traffic
- Password reset needs for users and administrators
- TOTP reset requirements
- New or suspicious appliance-originated connections
- Traffic capture artifacts or unusual scripts in temporary directories
Which Indicators Should Defenders Prioritize?
SonicWall’s advisory lists indicators involving login and logout API paths, suspicious /wsproxy entries with HTTP 101 responses, hotfix rollback entries containing path traversal values, and modified /var/lib/unit/conf.json routes.

Further research findings add malware and post-exploitation context. Security teams should look for:
- deploy_new.py, associated with KNUCKLEBALL
- xzfind, associated with ROOTRUN
- Temporary Java payloads such as agent_wp8.jar and agent_wp9.jar
- Unexpected traffic capture files or scripts in /var/tmp
- Custom NGINX Unit routes pointing to local webshell infrastructure
- Appliance-originated authentication attempts to internal systems
These indicators may vary by intrusion, but they provide a strong starting point for triage, containment, and scoping.
How Can SOCRadar Help Prioritize Response?
SonicWall SMA appliances are often internet-facing, so exposure visibility matters during zero-day response. Teams need to identify reachable SonicWall assets, confirm patch status, and track whether vulnerable services remain exposed.
SOCRadar’s Attack Surface Management (ASM) helps organizations discover and prioritize exposed digital assets, including internet-facing systems, cloud infrastructure, SaaS applications, identities, and third-party integrations. For this campaign, ASM can help identify externally reachable SonicWall assets that require immediate validation.

SOCRadar’s ASM, Company Vulnerabilities
Also, SOCRadar’s Cyber Threat Intelligence module helps teams monitor critical CVEs, exploit alerts, affected technologies, and threat activity. For CVE-2026-15409 and CVE-2026-15410, this context can support prioritization based on exploitation status, exposure, and vendor guidance.
