SonicWall
Vulnerabilities in SonicWall firewalls, Secure Mobile Access (SMA) appliances, and SSL-VPN gateways — perimeter gear that lands on CISA's Known Exploited Vulnerabilities catalog with unusual regularity and gets targeted by ransomware crews within days of disclosure.
SonicWall SMA1000 unauthenticated SSRF in Work Place portal
An unauthenticated server-side request forgery in the SonicWall SMA1000 Work Place web interface lets a remote attacker force the appliance to make requests to attacker-chosen destinations. Actively exploited; on CISA KEV.
SonicWall SMA1000 post-authentication OS command injection
A post-authentication OS command injection in the SonicWall SMA1000 lets an administrator execute arbitrary OS commands on the appliance. Actively exploited alongside CVE-2026-15409; on CISA KEV.

Volexity ties SonicWall SMA1000 zero-days to UTA0533
Volexity attributes the SonicWall SMA1000 zero-day chain to UTA0533, first observed exploitation on June 22, four custom implants staged after.

SonicWall SMA1000: Volexity names UTA0533, IoC list out
Volexity attributes the SMA1000 pre-disclosure exploitation to a new actor, UTA0533, active since June 22 — and publishes the toolkit for defenders to hunt.

SonicWall SMA1000: what Rapid7 saw before disclosure
Rapid7 caught the SMA1000 zero-day exploitation before SonicWall's advisory. Attackers took credentials, MFA seeds, and pivoted to internal domain controllers.

SonicWall SMA1000 zero-days on CISA KEV: patch by July 17
Two SMA1000 flaws — a CVSS-10.0 unauthenticated SSRF and a post-auth code injection — hit CISA KEV today. Patch to 12.4.3-03453 or 12.5.0-02835 before July 17.