WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More – CYBERDEFENSA.MX

A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools.

The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being used before defenders had time to patch.

Here is the full recap of what broke, what was exploited, and what needs attention now.

⚡ Threat of the Week

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code – Searchlight Cyber disclosed a pre-authenticated remote code execution vulnerability in WordPress Core that can be exploited anonymously on a standard WordPress installation, without requiring any plugins or other special conditions. It is a combination of CVE-2026-63030 (REST API batch-route confusion) and CVE-2026-60137 (SQL injection in WordPress core) that can be chained to turn an anonymous request into code execution. watchTowr said it’s already seeing proof-of-concept (PoC) exploits in circulation and that it’s beginning to see the first signs of in-the-wild exploitation. «This is going to hurt,» watchTowr CEO Benjamin Harris said. «WordPress runs on hundreds of millions of websites globally. Some of those will be auto-patched by their hosting providers, but plenty will not, and that is where the damage will be done. Our advice is simple: patch as fast as you possibly can, and do not stop there. Put the controls and investigations in place to determine whether an attacker got there first and to detect and remove any backdoors that may already have been dropped before you patched.» The cybersecurity company said it’s the latest example of vulnerabilities being surfaced by AI-assisted tooling and how the technology is being abused by attackers to weaponize them.

🔔 Top News

  • SonicWall SMA Zero-Days Exploited as 0-Days – A previously undocumented threat actor codenamed UTA0533 has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior to their public disclosure since June 22, 2026. The discovery was made following an incident response investigation initiated earlier this month. The impacted organization has not been identified. «This threat actor was observed using multiple zero-day exploits, malware designed specifically for SonicWall SMA VPN appliances, as well as other attacker tradecraft,» Volexity said. The vulnerabilities in question are CVE-2026-15409 (CVSS score: 10.0) and CVE-2026-15410 (CVSS score: 7.2), both of which could be chained to facilitate arbitrary command execution and take over susceptible devices. Patches for both vulnerabilities were released by SonicWall last week.
  • DoS Flaw in OpenSSL – The Okta Red Team disclosed details of HollowByte, a denial-of-service (DoS) flaw in OpenSSL. «By sending a malicious payload of just 11 bytes, a remote, unauthenticated attacker can force a server to allocate disproportionate chunks of memory before any security handshake even begins,» Okta said. Put differently, an unauthenticated attacker — through 11 bytes of carefully crafted data — can convince OpenSSL to reserve up to 128 KB of heap memory for a handshake message that never actually arrives, causing a server to exhaust available RAM and trigger a DoS condition. The OpenSSL team resolved the issue in versions 4.0.1, 3.6.3, 3.5.7, 3.4.6, and 3.0.21. «Instead of trusting the header outright, OpenSSL now grows the buffer only as bytes actually land on the wire. A claim with no follow-through now costs the server nothing,» Okta said.
  • CISA Adds New SharePoint RCE Zero-Day to KEV Catalog – The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 19, 2026. The vulnerability, CVE-2026-58644 (CVSS score: 9.8), is a critical deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute arbitrary code. Patches for the flaw have been released as part of the Patch Tuesday updates released on July 14, 2026. Microsoft revised its bulletin to clarify that CVE-2026-58644 has been exploited in the wild, meaning the shortcoming was weaponized as a zero-day prior to the fixes becoming available. The development came as Microsoft shipped its largest Patch Tuesday on record, addressing 622 vulnerabilities.
  • OkoBot Malware Framework Infects Windows to Phish Crypto Seed Phrases – A new malware framework called OkoBot is designed to capture the contents of cryptocurrency wallet windows. OkoBot is an updated version of TookPS, which is a downloader for retrieving malicious commands and scripts from attacker-controlled servers to further propagate attacks, including a Python-based infostealer and a remote access trojan called TeviRAT. «This campaign differs from previous activity in that it uses a new framework to deliver all malicious modules and orchestrate them via an SSH tunnel,» Kaspersky said. «In total, the framework includes more than 20 malicious payloads and implants, covering a wide variety of functions. At the time of writing, the threat remains active.» The infection chain makes use of ClickFix and malware distributed through GitHub that masquerades as legitimate software for initial access. It also comes with a web browser extensions loader to deliver Rilide, a browser-based stealer, as well as inject an implant into Trezor Suite, Ledger Wallet, and Ledger Live processes to collect seed phrases, log keystrokes and clipboard content, take screenshots, and capture keystrokes and the video stream of the target application’s window using the OkoSpyware module. Hundreds of victims of the OkoBot campaign have been detected in more than 25 countries, with the highest concentration in Brazil, Vietnam, Canada, Mexico, and Türkiye. The activity remains unattributed.
  • NadMesh Scans Exposed AI Services for Cloud Keys and Kubernetes Tokens – A new Go botnet called NadMesh has been observed hunting for exposed AI services related to ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio to steal AWS keys and Kubernetes tokens. «It folds scanning, exploitation, and credential/AI-service intelligence harvesting into a single autonomous platform,» QiAnXin XLab said. «On the victim, the bot agent establishes persistence along three independent paths: an SSH public-key backdoor (.ssh/authorized_keys), persistence files in multiple locations (/dev/shm/.a, /var/tmp/.a, /tmp/.a), and hidden cron watchdogs (/etc/cron.d/.sys_monitor, /etc/cron.d/.s).»

‎️🔥 Trending CVEs

Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild.

Check the list, patch what you have, and hit the ones marked urgent first – CVE-2026-63030, CVE-2026-60137 (WordPress Core), CVE-2026-58644, CVE-2026-56164 (Microsoft SharePoint Server), CVE-2026-56155 (Microsoft Active Directory Federation Services), CVE-2026-53412 (Zoom Desktop Client for Windows and Zoom VDI Client for Windows), CVE-2026-44747, CVE-2026-27690, CVE-2026-44761 (SAP), CVE-2026-57219, CVE-2026-57221 (RabbitMQ), CVE-2026-59208, CVE-2026-54305 (n8n), CVE-2026-60105 (Monsta FTP), CVE-2026-14960, CVE-2026-14961 (tdeio64.sys driver), CVE-2026-33894, CVE-2026-33895 (Digital Bazaar node-forge), CVE-2026-6875 (ServiceNow AI Platform), CVE-2026-42533, CVE-2026-60005, CVE-2026-56434 (F5 NGINX Plus and NGINX Open Source), CVE-2026-20296, CVE-2026-20297 (Splunk Enterprise), CVE-2026-15265 (Tenable Agent), CVE-2026-6423 (ESET Inspect Connector), CVE-2026-15053 (Tanium Server), CVE-2026-44909, CVE-2026-59173, CVE-2026-59762 (HTTP/2 server implementations), CVE-2026-14890 (SGLang), CVE-2026-14266 (7-Zip), CVE-2026-59084 (Apache Tomcat), CVE-2026-15682 (AnyDesk), and CVE-2026-54523 (Kyverno).

🎥 Cybersecurity Webinars

  • Your AI Agent Has Credentials. Can You Stop It When It Goes Rogue? Hands-on testing of OpenClaw shows how agentic AI can expose secrets, bypass safety controls, and create a powerful new attack surface. Join Okta Threat Intelligence Director Jeremy Kirk to examine how attackers are abusing AI agents and learn practical ways to control access, enforce least privilege, detect shadow AI, and shut down risky agents before they cause damage.
  • When AI Ships 50× More Code, Human Review Stops Scaling → AI-assisted development is pushing code production beyond what traditional security reviews and CVE-driven remediation can handle. This webinar gives security leaders a practical framework for governing the expanding attack surface, building secure-by-default controls, and enabling teams to develop at machine speed without surrendering control of software risk.

📰 Around the Cyber World

  • New Campaign Delivers Remcos RAT – A new malware distribution campaign has abused the credibility of government institutions to increase the likelihood of infection success. The activity targets Indian businesses and taxpayers using Goods and Services Tax (GST)-related themes to distribute malware. «The threat actors impersonated legitimate government departments and distributed malicious emails disguised as official notifications related to taxation, refunds, compliance requirements, and regulatory matters,» Seqrite Labs said. «The threat actors employ convincing documents and filenames that closely resemble official GST notifications, making it difficult for recipients to distinguish malicious content from legitimate government correspondence.» The end goal is to deploy Remcos RAT and steal sensitive information.
  • India’s Kudankulam Nuclear Power Plant Suffers a Data Leak – The Kudankulam Nuclear Power Plant located in the Indian state of Tamil Nadu suffered an accidental exposure after Reliance Infra (RPOWER) got hit by a ransomware group called World Leaks, a spin-off of Hunters International, which, in turn, is another variant of the Hive ransomware family. The leak consists of 18,997 files, totalling 14.3GB of data, per security researcher Rakesh Krishnan. They contain purported blueprints for the ventilation and cooling systems used in Unit 3 and Unit 4, along with a complete floor layout of a «common control room». It’s assessed that Reliance Infra was not impacted directly, but rather through a third-party vendor named Yotta.
  • Blind Eagle Shows No Signs of Stopping – Nearly a year after Blind Eagle’s activities were documented, a new report from LevelBlue has found the threat actor to be active, moving part of its VBScript delivery infrastructure onto the Russian bulletproof hosting provider Proton66 as of June 2025. The group has also devised a bespoke string-obfuscation scheme, a RunPE loader built entirely on a bare AutoIt3 interpreter, and an upgraded version of AsyncRAT that introduces Windows Notification Facility (WNF) process injection, a custom Base28 payload encoding, a full Hidden VNC (HVNC) banking-fraud module with browser profile cloning, and a Chrome App-Bound Encryption (ABE) bypass, per LevelBlue.
  • Qilin Ransomware Use of EDR Killer – Qilin ransomware operations have been observed adopting aggressive, kernel-level defense evasion to blind and disable endpoint security products before its main ransomware payload is executed on a victim’s network. The EDR killer, packed via the Shanya packer, is sold on illicit marketplaces for $2,000. «The EDR killer compares the returned locale to a known locale blacklist to avoid attacking any Commonwealth of Independent States (CIS) countries such as Russia and Belarus,» Flashpoint said. «The EDR killer then writes a vulnerable driver to disk and loads this driver via Service Manager. This driver is the ThrottleStop driver from TechPowerUp LLC’s free and legitimate application of the same name, used to bypass CPU throttling. However, the driver suffers from a vulnerability, allowing the malware to map physical memory to kernel-mode virtual memory to perform direct kernel read and write operations.» Also put to use is a custom Rust-written loader that performs reflective Portable Executable (PE) loading of the ransomware payload.
  • DefiTuna Suffers a Security Incident – DeFiTuna, an Automated Market Maker (AMM) on the Solana blockchain, was exploited on July 16, 2026, for $569,601 USDC. «The attackers created a highly illiquid TUNA/USDC pool and used it as the destination for borrowed USDC routed through Jupiter,» CertiK said. «Because the swap returned only a negligible amount of TUNA, DeFiTuna’s value calculation rounded the position’s total assets down to zero. The protocol then incorrectly treated the position as healthy, allowing the attackers to bypass the solvency check and withdraw the USDC through attacker-controlled liquidity positions.»
  • Next.js Opts for Scheduled Security Releases – Vercel announced that Next.js is adopting a formal security release program, replacing ad-hoc patches for security fixes following a surge in AI-assisted vulnerability discovery. «This kind of scheduled, pre-announced security release has become standard practice for major open source projects, and we think it’s the right model for Next.js at its current scale,» Vercel said. «Here’s what you can expect going forward: roughly once a month, we’ll publish advance notice of upcoming security releases. Each announcement will include the expected release timeline and the highest anticipated severity among the vulnerabilities it covers. This lead time lets you plan your upgrades, and it lets us coordinate with hosting providers and other platform partners to deploy mitigations, such as firewall rules, that help protect applications that haven’t been patched yet.»
  • Disguised Gambling Apps Target Brazil – A new analysis from 9to5Mac has revealed more than 60 «jacket apps» on the App Store that are disguised as simple games and utilities that become online betting platforms when accessed from Brazilian IP addresses. Most of the apps are published by developer accounts with only a single App Store listing, with further investigation linking them to a «public GitHub repository containing instructions for a Cursor agent to create simple, vibe-coded apps that serve as fronts for the betting platforms.»
  • Ransomware Stats for Q2 2026 – The Gentlemen has become the most active ransomware group for Q2 2026, claiming 300 victims, surging past Qilin (289), DragonForce, Akira, and LockBit. Another group named Deadlock resurfaced after 11 months of silence with 75 June victims. In all, the top 11 tracked groups accounted for 1,368 of Q2’s victim claims across 99 countries. «What sets The Gentlemen apart is its packaging, where affiliates receive ready-made tools that ship and update faster than most competing programs,» ReliaQuest said.
  • 2 Members of Chinese Money Laundering Network Charged with Laundering $43M in Investment Fraud – The U.S. Justice Department unsealed charges against a New York man and woman for conspiracy to launder money derived from cyber investment fraud scams. «Between 2020 and 2022, Zhuoying Chen, 27, of Brooklyn, New York, and Haojie Zhang, 38, of Queens, New York, managed a network of more than a dozen individuals based in Queens and Brooklyn, who opened 140 bank accounts in the name of approximately 45 shell companies to launder at least $43 million in proceeds of investment scams,» the department said. «Then, Chen and Zhang allegedly conspired with China-based co-conspirators to transfer the funds involved in the fraud schemes abroad. The fraud schemes consist of perpetrators contacting victims via messaging services or social media applications. The perpetrators would initiate relationships with the victims and gain their trust, convincing victims to send money for lucrative investment opportunities. The perpetrators would show the victims fake profits on the purported investment and encourage the victims to invest more. The perpetrators would then steal the victim’s funds.»
  • U.S. Cyber Agency Uses Mythos to Audit Government Code – Reuters reported that the U.S. Cybersecurity and Infrastructure Security Agency (CISA) is using Anthropic’s AI model Mythos to audit government software for defects that could potentially offer a pathway for foreign spies and cybercriminals, citing three people familiar with the matter.

🔧 Cybersecurity Tools

  • VisionSec → It is an open-source, self-hosted threat intelligence platform that combines domain monitoring, phishing detection, exposed-service scanning, GitHub secret discovery, breach checks, email security assessments, and Telegram alerts in a modular Docker-based deployment. The project remains at an early stage, with no published releases at the time of writing.
  • owLSM → It is an open-source Linux security agent that uses eBPF LSM to run stateful Sigma rules inside the kernel, block malicious activity, correlate events across multiple probes, and provide detailed context for security monitoring and response.

Disclaimer: This is strictly for research and learning. It hasn’t been through a formal security audit, so don’t just blindly drop it into production. Read the code, break it in a sandbox first, and make sure whatever you’re doing stays on the right side of the law.

Conclusion

That is the week: exposed systems, weak checks, old tools, and attackers moving faster than patch cycles.

Review what applies, fix the obvious gaps first, and assume anything public has already been tested.

SonicWall SMA Zero-Days explotado antes de la divulgación para obtener acceso raíz – CYBERDEFENSA.MX

A un actor de amenazas previamente indocumentado se le ha atribuido la explotación de dispositivos VPN de la serie SonicWall Secure Mobile Access (SMA) 1000 recientemente divulgados como días cero antes de su divulgación pública desde el 22 de junio de 2026.

La empresa de ciberseguridad Volexity está rastreando la actividad bajo el nombre UTA0533. El descubrimiento se realizó luego de una investigación de respuesta a incidentes a principios de este mes. La organización afectada no ha sido identificada.

«Se observó que este actor de amenazas utiliza múltiples exploits de día cero, malware diseñado específicamente para dispositivos SonicWall SMA VPN, así como otras técnicas de ataque», dijeron los investigadores de seguridad Sean Koessel y Steven Adair. dicho en un análisis.

Las vulnerabilidades en cuestión son CVE-2026-15409 (puntuación CVSS: 10,0) y CVE-2026-15410 (puntuación CVSS: 7,2), las cuales podrían encadenarse para facilitar la ejecución de comandos arbitrarios y hacerse cargo de dispositivos susceptibles. SonicWall lanzó parches para ambas vulnerabilidades esta semana.

Ciberseguridad

Se han identificado dos dispositivos SonicWall SMA VPN pertenecientes a la entidad comprometida. La secuencia de acciones emprendidas por el actor de amenazas en estos dispositivos se enumera a continuación:

  • Aparato 1:

    • Escribiendo un ejecutable ELF llamado «/usr/bin/xzfind» el 22 de junio de 2026. El archivo es un setuid binario llamado ROOTRUN que permite a un usuario sin privilegios ejecutar comandos arbitrarios como root.
    • Escribir un segundo nombre de archivo «/usr/lib/python3.11/site-packages/deploy_new.py» (también conocido como KNUCKLEBALL), que contiene dos archivos JAR integrados que se inyectan en un proceso legítimo de SonicWall. Las dos cargas útiles son Suo5, un proxy HTTP de código abierto y un shell web Java personalizado similar a Behinder denominado ORANGETAIL. Los archivos JAR permiten a los atacantes interactuar con ellos a través de rutas URI accesibles desde Internet: «/workplace/error.jsp» y «/workplace/dialogs/errorDialog.jsp».
    • Establecer persistencia modificando el script legítimo «/etc/init.d/workplace startup» mediante el script Python descargado en el paso anterior.
    • Modificar el archivo de configuración de la unidad NGINX en «/var/lib/unit/conf.json» para agregar dos rutas que conducen a Suo5 y ORANGETAIL.
  • Aparato 2:

    • Realización de las mismas modificaciones en «/var/lib/unit/conf.json» identificadas en el primer dispositivo, aunque las rutas no arrojaron respuestas válidas.
    • Crear varios archivos en el directorio «/var/tmp», incluido uno («lib.sh») que inicia tcpdump para inspeccionar el tráfico LDAP no cifrado para extraer nombres de usuarios y contraseñas.

Se dice que el segundo dispositivo tiene menos artefactos luego de un reinicio el 2 de julio de 2026, lo que resulta en la eliminación de cualquier artefacto residente en la memoria y puertas traseras.

Volexity dijo que identificó archivos adicionales asociados con la explotación y la escalada de privilegios en la carpeta «/tmp» del primer dispositivo, con un archivo («/tmp/hypdate.b64») que presenta un exploit para CVE-2026-15410.

«Los archivos en /tmp eran propiedad de la cuenta sin privilegios utilizada por el servicio de base de datos interna del dispositivo», explicaron los investigadores. «Esto indicó que el actor de amenazas podría escribir y probablemente ejecutar archivos a través de ese contexto de servicio».

Un análisis más detallado de los registros y la memoria del sistema condujo al descubrimiento de CVE-2026-15409, que se ha descrito como una omisión de autenticación previa «/wsproxy» que permite que una solicitud externa no autenticada establezca un túnel WebSocket a servicios de solo host local en el dispositivo. En concreto, implica emitir una solicitud con un User-Agent de SMA Connect Agent y un valor de bmID que comienza con -3389.

El actor de amenazas puede abusar del acceso externo para acceder a los métodos definidos en el punto final «sysCtrl», lo que proporciona una vía para un acceso más profundo al explotar la inyección de comandos, la escalada de privilegios y las fallas de ejecución de código en el servicio de control SMA (es decir, CVE-2026-15410).

También se señala como parte del análisis un defecto de seguridad separado que puede permitir a un atacante eludir la autenticación en el servicio de control de SMA («servicio-ctrl»). Debido a que la contraseña de autenticación básica se deriva del identificador de hardware local del dispositivo («/sys/class/dmi/id/product_uuid»), un atacante con conocimiento de este UUID puede determinar la contraseña necesaria para la autenticación.

Lo que hace que esto sea trivial es que cualquiera puede leer el archivo «product_uuid», lo que permite a un usuario sin privilegios obtener el valor y descubrir la contraseña. Dicho esto, el valor UUID solo se observa para dispositivos físicos, lo que significa que los dispositivos virtuales no se ven afectados.

«Cabe señalar que esta omisión de autenticación no parece haber sido utilizada en el incidente observado», dijo Volexity. «En cambio, el atacante abusó de una vulnerabilidad diferente para leer el archivo ‘product_uuid’»

Además, UTA0533 se ha vinculado a la explotación de CouchDB, una base de datos que viene instalada como parte del dispositivo SMA y a la que se puede acceder a través de localhost. Aunque la operación exacta llevada a cabo por el actor de la amenaza aún no está clara, los indicios apuntan al uso del usuario de CouchDB para leer el archivo «product_uuid» y, en última instancia, eludir la autenticación.

Ciberseguridad

«Con esta capacidad, un atacante puede alcanzar y explotar servicios menos reforzados que se ejecutan en el dispositivo, como la aplicación Erlang en localhost:1050 o la aplicación ctrl-service en localhost:8188», Rapid7 dicho.

Un exploit de prueba de concepto (PoC) liberado por el proveedor de ciberseguridad establece la ejecución remota de código no raíz en dispositivos SonicWall SMA 1000 mediante la implementación del protocolo Erlang esperado por localhost:1050 y tunelándolo a través de WebSocket para lectura y escritura de archivos y ejecución de código arbitrario a través de llamadas RPC.

En total, toda la cadena de explotación se desarrolla de la siguiente manera:

  • Envíe una solicitud «/wsproxy» no autenticada con la cadena User-Agent que contiene el agente SMA Connect y el parámetro URI que comienza con bmID=-3389.
  • Establezca un túnel WebSocket para servicios exclusivos de host local.
  • Realice llamadas a CouchDB para leer y escribir archivos como el usuario «couchdb».
  • Prepare un archivo en «/tmp» como el usuario «couchdb» que leerá el archivo /sys/class/dmi/id/product_uuid una vez ejecutado mediante la explotación de CVE-2026-15409.
  • Escale a raíz explotando CVE-2026-15410, una falla de recorrido de ruta en el flujo de trabajo «remove_hotfix» de «ctrl-service» y obtenga la ejecución de comandos con privilegios elevados.

«UTA0533 combinó múltiples vulnerabilidades de día cero para comprometer los dispositivos SonicWall SMA VPN y obtener acceso a nivel de raíz», dijo Volexity. «Con acceso raíz, el actor de amenazas podría acceder a las credenciales almacenadas o en caché, capturar el tráfico de la red y potencialmente interceptar las credenciales procesadas por los dispositivos».

«Aunque UTA0533 demostró una capacidad significativa para comprometer los dispositivos SonicWall, la evidencia disponible sugiere que el actor de la amenaza tuvo menos éxito al moverse lateralmente o al obtener acceso a otros sistemas».

Los clientes de SonicWall están amenazados porque los atacantes explotan 2 días cero

Los clientes de SonicWall están intentando esquivar otro desafío de seguridad mientras los atacantes explotan un par de vulnerabilidades de día cero que han sido confirmadas por el proveedor.

La empresa reveló públicamente las vulnerabilidades: CVE-2026-15409 y CVE-2026-15410 – en un aviso de seguridad Martes. SonicWall le dio crédito a un empleado por descubrir los defectos, pero no dijo cuándo ocurrió el descubrimiento ni cuál fue el primer caso conocido de explotación.

Los investigadores de Rapid7 dijeron a CyberScoop que ambas vulnerabilidades fueron explotadas por primera vez el 22 de junio. «A partir de los casos que nuestro equipo ha observado, el objetivo probablemente sea el ransomware, aunque hemos impedido que los actores lograran la exfiltración y el cifrado», dijo Seth Lazarus, gerente senior de servicios de detección y respuesta de Rapid7.

Las tácticas, técnicas y procedimientos superpuestos de los ataques observados por Rapid7 indican que el mismo grupo de amenaza o atacante descubrió y explotó los días cero, agregó Lazarus.

SonicWall no respondió preguntas sobre los impactos de estos ataques hasta el momento, y la compañía no ha atribuido los ataques a un grupo conocido ni ha descrito los orígenes y motivaciones del atacante.

Sin embargo, el proveedor confirmó a CyberScoop que ambas vulnerabilidades se han encadenado para su explotación. Las vulnerabilidades que afectan a los dispositivos SonicWall SMA1000, incluido un defecto de gravedad máxima que permite a los atacantes realizar solicitudes autenticadas y una vulnerabilidad con clasificación 7.2 que permite la inyección de comandos autenticados.

«Cuando estos dos están encadenados, un atacante puede pasar de un acceso cero a un compromiso completo del sistema del dispositivo afectado», dijo Landon Rice, desarrollador senior de exploits en VulnCheck.

Ben Harris, fundador y director ejecutivo de watchTowr, dijo que dos características de las vulnerabilidades alimentan una sensación de temor. «Ambos fueron explotados como días cero antes de que las soluciones estuvieran disponibles, y juntos ofrecen un camino plausible para la ejecución remota de código desde Internet», dijo.

La Agencia de Seguridad de Infraestructura y Ciberseguridad agregó ambos días cero a su catálogo de vulnerabilidades explotadas conocidas Martes.

SonicWall alentó a los clientes a corregir las vulnerabilidades actualizando a la última versión del software, que lanzó tras la divulgación, y compartió algunos indicadores de compromiso para ayudar a los clientes a buscar posibles actividades maliciosas en sus sistemas.

«La velocidad de respuesta era una prioridad para nosotros», afirmó Bret Fitzgerald, director senior de comunicaciones globales de SonicWall. «A los pocos días de tomar conciencia del problema, nuestro equipo desarrolló un script que podemos ejecutar en nombre de los clientes afectados para ayudar con la resolución, y los esfuerzos de mitigación ya están en marcha».

SonicWall y los investigadores externos no han dicho cuántos clientes de SonicWall se ven afectados por las vulnerabilidades explotadas, pero el proveedor dijo que ya investigó múltiples casos de explotación activa.

Fitzgerald dijo que la compañía monitorea alrededor de un millón de sensores en todo el mundo y que «los dispositivos SMA1000 representan un subconjunto muy pequeño de esa huella, menos de 5000 unidades».

SonicWall dijo que el personal de soporte también está ayudando a los clientes a resolver casos de actividad sospechosa, advirtiendo que aplicar parches por sí solos no es suficiente.

El proveedor y sus clientes se han visto afectados durante años por una avalancha de días cero explotados activamente y defectos previamente revelados en dispositivos SonicWall. En 2025, un actor de amenazas no revelado patrocinado por el estado invadió el entorno de nube de la empresa y robó las configuraciones de firewall de todos los clientes de SonicWall.

Se han agregado diecisiete defectos que afectan a los productos del proveedor al catálogo de vulnerabilidades explotadas conocidas de CISA desde finales de 2021. Se sabe que diez de esos defectos se utilizan en campañas de ransomware, según CISA, incluida una ola de alrededor de 40 ataques de ransomware Akira entre mediados de julio y principios de agosto.

«Como siempre», dijo Harris, «cuando se confirma que algo ya está explotado en la naturaleza, lo mínimo indispensable es aplicar parches y se debe asumir que se ha producido una infracción».

Matt Kapko

Escrito por Matt Kapko

Matt Kapko es reportero de CyberScoop. Su ámbito incluye delitos cibernéticos, ransomware, defectos de software y (mala) gestión de vulnerabilidades. El californiano de toda la vida comenzó su carrera periodística en 2001 con paradas anteriores en Cybersecurity Dive, CIO, SDxCentral y RCR Wireless News. Matt tiene una licenciatura en periodismo e historia de la Universidad Estatal de Humboldt.

Dos SonicWall SMA 1000 Zero-Day explotados, uno podría habilitar los comandos de administración – CYBERDEFENSA.MX

SonicWall tiene prevenido de explotación activa de dos vulnerabilidades de día cero que afectan a los dispositivos de la serie Secure Mobile Access (SMA) 1000, una de las cuales podría explotarse para lograr la ejecución de comandos arbitrarios.

Las vulnerabilidades se enumeran a continuación:

  • CVE-2026-15409 (Puntuación CVSS: 10,0): una vulnerabilidad de falsificación de solicitudes del lado del servidor (SSRF) que un atacante remoto no autenticado podría aprovechar para provocar que el dispositivo realice solicitudes a una ubicación no deseada.
  • CVE-2026-15410 (Puntuación CVSS: 7,2): una vulnerabilidad de inyección de código posterior a la autenticación basada en Appliance Management Console (AMC) que un atacante remoto autenticado podría aprovechar para ejecutar comandos arbitrarios del sistema operativo como administrador bajo ciertas condiciones.

SonicWall dijo que ha «investigado múltiples casos que indican la explotación activa de las vulnerabilidades», instando a los clientes a aplicar las correcciones lo antes posible. Los parches están disponibles en las siguientes versiones:

  • 12.4.3-03453 (plataforma-hotfix) y versiones superiores
  • 12.5.0-02835 (plataforma-revisión) y versiones superiores

También se insta a los usuarios a realizar un análisis forense exhaustivo del sistema para determinar la presencia de cualquier indicador de compromiso (IoC) asociado con la explotación.

Ciberseguridad
  • Si en extraweb_access.log se mencionan solicitudes a /__api__/login o /__api__/logout con estado http 200
  • Si en extraweb_access.log se mencionan solicitudes a /wsproxy con parámetros de host sospechosos con estado http 101
  • Si en ctrl-service.log se mencionan reversiones de revisiones con nombres de recorrido de ruta
  • Si /var/lib/unit/conf.json contiene rutas para /__api__/login o /__api__/logout (estos URI no existen en la configuración legítima)

Si uno de estos indicadores está presente, se recomienda volver a crear imágenes de los dispositivos físicos o implementar dispositivos virtuales, cambiar las contraseñas de usuario y administrador y restablecer los tokens de contraseña de un solo uso basados ​​en el tiempo.

A Adam Babis, del equipo de respuesta a incidentes de seguridad de productos (PSIRT) de SonicWall, se le atribuye el mérito de descubrir e informar las fallas. SonicWall también reconoció las contribuciones de Sean Koessel y Steven Adair de Volexity para ayudar a avanzar en la investigación interna e identificar un IoC adicional.

El desarrollo ha llevado a la Agencia de Seguridad de Infraestructura y Ciberseguridad de EE. UU. (CISA) a agregar los dos defectos de sus vulnerabilidades explotadas conocidas (KEV), que exige que las agencias del Poder Ejecutivo Civil Federal (FCEB) apliquen las correcciones antes del 17 de julio de 2026.