Overview
- Volexity found that attackers began exploiting two previously unknown SMA1000 flaws as early as June 22, 2026 to gain root on affected devices.
- The chain started with a pre‑auth /wsproxy SSRF/WebSocket bypass that reached localhost services including CouchDB and then used a ctrl‑service path‑traversal/command injection to escalate to root.
- With root the attackers installed bespoke tooling including a dropper called KNUCKLEBALL, a Java webshell named ORANGETAIL, a Suo5 proxy, and a setuid privilege tool called ROOTRUN.
- SonicWall issued hotfixes on July 14 and CISA added CVE‑2026‑15409 and CVE‑2026‑15410 to its KEV catalog while researchers and vendors published exploit proofs, IoCs, and detection rules.
- Organizations are urged to apply updates immediately, hunt logs and filesystem artifacts, reimage or replace compromised appliances, and reset passwords and TOTP tokens because patches alone may not remove active implants.