
Unknown Threat Actor Exploits Zero-Day Vulnerabilities in SonicWall SMA 1000 Series VPN Appliances
CybersecurityZero-DayVulnerabilitiesVPNExploitation
A previously unknown threat actor, tracked as UTA0533 by cybersecurity firm Volexity, exploited zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances prior to their public disclosure. The exploitation began on June 22, 2026, and was identified during an incident response investigation. The attacks targeted undisclosed organizations to gain root-level access to the affected systems. No specific CVE IDs or additional technical details about the vulnerabilities were provided in the report. The activity highlights the risk of undisclosed zero-day exploitation in enterprise VPN infrastructure.