PT-2026-61591 · Undefined · Undefined
CVE-2026-154010
·
Published
2026-07-20
·
Updated
2026-07-20
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
#ParsedReport #CompletenessLow
17-07-2026
Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation
Report completeness: Low
Actors/Campaigns:
Uta0533
Threats:
Xzfind tool
Rootrun tool
Knuckleball
Suo5 tool
Behinder
Orangetail
Victims:
Vpn appliances, Network infrastructure, Organizations
CVEs:
CVE-2026-15409 [Vulners]
CVSS V3.1: 10.0,
Vulners: Exploitation: True
X-Force: Risk: Unknown
X-Force: Patch: Unknown
CVE-2026-15410 [Vulners]
CVSS V3.1: 7.2,
Vulners: Exploitation: True
X-Force: Risk: Unknown
X-Force: Patch: Unknown
CVE-2026-154010 [Vulners]
CVSS V3.1: Unknown,
Vulners: Exploitation: Unknown
X-Force: Risk: Unknown
X-Force: Patch: Unknown
ChatGPT TTPs:
do not use without manual check
T1037.004, T1040, T1055, T1057, T1059.004, T1059.006, T1068, T1070.004, T1090.001, T1105, have more...
IOCs:
File: 10
IP: 8
Hash: 4
Soft:
Volexity Volcano, nginx, Unix
Algorithms:
md5, aes, base64, sha256, aes-128-ecb, sha1
Functions:
Volexity, setuid, getMethod
Languages:
python, java
Platforms:
x64
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Undefined