SonicWall zero-days used to install custom malware
Two zero-day flaws in SonicWall SMA1000 appliances were exploited from June 22 to install custom malware, weeks before SonicWall issued hotfixes on July 14.
Two zero-day vulnerabilities in SonicWall SMA1000 secure remote access appliances, tracked as CVE-2026-15409 and CVE-2026-15410, were exploited beginning as early as June 22 to install custom malware, according to an investigation assisted by cybersecurity firm Volexity. SonicWall published an advisory and released hotfixes on July 14.
Volexity attributed the attacks to a group it tracks as UTA0533. The firm reported the attackers used the two zero-days to deploy a custom implant named KnuckleBall, which injected additional tools into legitimate processes on compromised appliances. Those tools included a Java webshell called OrangeTail and an open-source proxy known as Suo5.
The vulnerabilities allowed attackers to obtain root access on affected SMA1000 appliances. “With root access, the threat actor could access stored or cached credentials, capture network traffic, and potentially intercept credentials processed by the appliances,” Volexity wrote.
Volexity published indicators of compromise and technical details after completing its investigation. The firm has not linked UTA0533 to any previously identified threat actor and described the activity as more consistent with nation-state advanced persistent threat behavior than with financially motivated cybercrime. Volexity added that available evidence suggests the actor had limited success moving laterally or accessing other systems.
SonicWall made hotfix releases available on July 14. The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-15409 and CVE-2026-15410 to its Known Exploited Vulnerabilities catalog, which now lists 17 vulnerabilities affecting SonicWall products.
Volexity recommended that administrators apply the vendor hotfixes and review the published indicators of compromise to check for signs of intrusion on SMA1000 devices.








