THE article discusses critical vulnerabilities in SonicWall SMA 1000 appliances exploited in a zero-day attack campaign leading to the deployment of KNUCKLEBALL malware. The two primary vulnerabilities, CVE-2026-15409 and CVE-2026-15410, allow attackers root-level access and remote code execution. The campaign, linked to a threat actor identified as UTA0533, began on June 22, 2026, and involved credential gathering and attempts to pivot to internal systems.
SonicWall has advised users to apply required hotfixes and conduct forensic analysis while highlighting the urgency of the situation, as both vulnerabilities have been added to CISA's Known Exploited Vulnerabilities catalog. Security teams are urged to prioritize security checks on internet-facing appliances and assess for signs of compromise.