SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch
Reported exploitedSMA1000 secure remote access appliancesUTA0533Our summary
Two critical zero-day vulnerabilities in SonicWall secure remote access appliances were actively exploited by a threat actor for several weeks before being patched. According to Volexity, attackers used CVE-2026-15409 and CVE-2026-15410 to deploy custom malware like KnuckleBall and gain unauthorized access to systems. SonicWall issued hotfixes on July 14 after the exploitation was discovered as early as June 22. CISA has also added these flaws to its Known Exploited Vulnerabilities catalog.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.