SonicWall Zero-Days Exploited to Deliver Custom Malware Before Patch Release
Two zero-day vulnerabilities in SonicWall appliances were exploited by threat actors for several weeks before patches were released, according to cybersecurity firm Volexity. The vulnerabilities, identified as CVE-2026-15409 and CVE-2026-15410, affected SMA1000 secure remote access appliances. SonicWall issued a public advisory on July 14, alerting customers to the exploitation of these flaws. Volexity, which assisted in the investigation, attributed the attacks to a threat actor it tracks as UTA0533. The exploitation reportedly began as early as June 22. The attackers deployed custom malware named KnuckleBall, which injected additional tools into legitimate processes. Despite the significant capability demonstrated by UTA0533 in compromising the appliances, the group was reportedly less successful in moving laterally or accessing other systems. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added these vulnerabilities to its Known Exploited Vulnerabilities catalog.