SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch
SonicWall zero-days CVE-2026-15409 and CVE-2026-15410 exploited for weeks to deliver custom malware KnuckleBall.
Summary
Two previously unknown vulnerabilities in SonicWall SMA1000 appliances (CVE-2026-15409 and CVE-2026-15410) were exploited in the wild for weeks before patches were released on July 14. Threat actor UTA0533 deployed custom malware named KnuckleBall alongside webshell OrangeTail and proxy Suo5 to gain root access and steal credentials. Evidence suggests APT-like activity rather than cybercriminal motivation, though lateral movement was limited.
Full text
Two recently patched SonicWall appliance zero-days were exploited by threat actors for weeks before patches were released, according to cybersecurity firm Volexity. SonicWall released a public advisory for the vulnerabilities on July 14, informing customers that CVE-2026-15409 and CVE-2026-15410 had been exploited in the wild. Remote, unauthenticated attackers can exploit the flaws to hack SMA1000 secure remote access appliances. SonicWall has made available hotfix releases to address the security holes. Volexity, which assisted the vendor’s investigation into the attacks, attributed the exploitation of the zero-days to a threat actor it tracks as UTA0533. The security firm believes exploitation started as early as June 22. The company on Friday shared IoCs and other technical details related to the attacks, but it has not linked UTA0533 to any known threat actor and the group’s motivation remains unclear. However, based on Volexity’s description, the attack appears more consistent with state-sponsored APT activity rather than a profit-driven cybercrime operation.Advertisement. Scroll to continue reading. Once the attackers compromised the targeted SonicWall appliances, they deployed custom malware named KnuckleBall, which injected two other tools into legitimate processes: a tailored Java webshell named OrangeTail, and an open source proxy named Suo5. “With root access, the threat actor could access stored or cached credentials, capture network traffic, and potentially intercept credentials processed by the appliances,” Volexity said. The security firm added, “Although UTA0533 demonstrated significant capability in compromising the SonicWall appliances, available evidence suggests the threat actor was less successful moving laterally or gaining access to other systems.” CISA has added CVE-2026-15409 and CVE-2026-15410 to its KEV catalog, which currently includes 17 flaws affecting SonicWall products. Related: WP2Shell WordPress Vulnerabilities Exploited in the Wild Related: Fresh SharePoint Vulnerability Exploited Soon After Disclosure Related: Splunk, Zoom Patch Critical Vulnerabilities Related: Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs WP2Shell WordPress Vulnerabilities Exploited in the WildTwo Scattered Spider Hackers Sentenced to Jail in UK‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process KillingChina’s Top Cybersecurity Firms Hit by Mounting Military Procurement BansTrend Micro, Tanium, ESET and Tenable Patch Severe Product VulnerabilitiesUS Charges Russian Individuals and Firms for Running Cybercrime ServicesWhite House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination InitiativeICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell Latest News Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI SoftwareOpenSSL Silently Fixes ‘HollowByte’ DoS VulnerabilityNew Index Tracks Material Breaches — And Refuses to Add Up the LossesErnst & Young Data Breach Affects Personal, Financial InformationWatch on Demand: Cloud & Data Security SummitCapital One Open Sources AI-Powered ‘VulnHunter’ Security ToolHugging Face Hacked in Autonomous AI AttackChrome 150 Update Patches Severe Memory Safety Bugs Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Closing the Exploitation Gap July 22, 2026 Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the MoveJazz has named Sean Robinson, Rickie Goyal, Danielle Guetta, Shani Nago, and Lior Magram as VPs and Michael Calev as COO.AJ Shipley has been appointed Chief Product Officer at CrowdStrike.Brinqa has named Ron Dovich as Chief AI and Automation Officer, David Allen as CTO, Steve Biagioni as CFO, and James Walta as VP of Product.More People On The MoveExpert Insights Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. (Tod Beardsley) The Shift Toward Business-Aligned Risk Management Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. (Steve Durbin) How to Conduct a Successful Audit of AI-Driven Software Development As AI-generated code becomes commonplace, CISOs need new audit strategies to measure developer practices, govern AI tool usage, and identify software risks before they reach production. (Matias Madou) Frontier AI: Six Questions Every Enterprise Should Ask Security Vendors From model selection and automation to validation and measurable results, the right questions can help enterprises separate genuine AI capabilities from marketing hype. (Joshua Goldfarb) The AI Token Costs That Can Break Cybersecurity As cybersecurity platforms embrace agentic AI, organizations must balance detection performance against the escalating costs of token consumption, deployment architecture, and AI credits. (Danelle Au) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- cve — CVE-2026-15409
- cve — CVE-2026-15410
- malware — KnuckleBall
- malware — OrangeTail
- malware — Suo5