Malware & Threats

SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch

The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533.

SonicWall firewalls exposed

Two recently patched SonicWall appliance zero-days were exploited by threat actors for weeks before patches were released, according to cybersecurity firm Volexity.

SonicWall released a public advisory for the vulnerabilities on July 14, informing customers that CVE-2026-15409 and CVE-2026-15410 had been exploited in the wild.

Remote, unauthenticated attackers can exploit the flaws to hack SMA1000 secure remote access appliances. SonicWall has made available hotfix releases to address the security holes.

Volexity, which assisted the vendor’s investigation into the attacks, attributed the exploitation of the zero-days to a threat actor it tracks as UTA0533. 

The security firm believes exploitation started as early as June 22.

The company on Friday shared IoCs and other technical details related to the attacks, but it has not linked UTA0533 to any known threat actor and the group’s motivation remains unclear. However, based on Volexity’s description, the attack appears more consistent with state-sponsored APT activity rather than a profit-driven cybercrime operation.

Advertisement. Scroll to continue reading.

Once the attackers compromised the targeted SonicWall appliances, they deployed custom malware named KnuckleBall, which injected two other tools into legitimate processes: a tailored Java webshell named OrangeTail, and an open source proxy named Suo5.

“With root access, the threat actor could access stored or cached credentials, capture network traffic, and potentially intercept credentials processed by the appliances,” Volexity said. 

The security firm added, “Although UTA0533 demonstrated significant capability in compromising the SonicWall appliances, available evidence suggests the threat actor was less successful moving laterally or gaining access to other systems.”

CISA has added CVE-2026-15409 and CVE-2026-15410 to its KEV catalog, which currently includes 17 flaws affecting SonicWall products.

Related: WP2Shell WordPress Vulnerabilities Exploited in the Wild

Related: Fresh SharePoint Vulnerability Exploited Soon After Disclosure

Related: Splunk, Zoom Patch Critical Vulnerabilities

Related: Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day

Related Content

Malware & Threats

Hackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts.

Vulnerabilities

CVE-2026-58138 is an unauthenticated remote code execution vulnerability that attackers can exploit via inline workflow definitions.

Vulnerabilities

Remote, unauthenticated attackers can exploit the vulnerability to bypass authentication via crafted requests.

Mobile & Wireless

Google announced patches for the exploited privilege escalation vulnerability (CVE-2026-58704) on September 15.

Malware & Threats

US, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C&C.

Vulnerabilities

CVE-2026-87886 is a high-severity insecure file permissions flaw that can lead to local privilege escalation.

Vulnerabilities

The vulnerability, tracked as CVE-2026-5430, can be exploited to gain access to valuable enterprise data.

Malware & Threats

The hackers staged numerous scripts for reconnaissance and CVE probing, along with brute-force utilities and privilege escalation tools.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version