A zero-day exploit chain has been identified, targeting SonicWall SMA 1000 appliances, leading to the deployment of custom malware. The threat actor, referred to as UTA0533, exploited two vulnerabilities (CVE-2026-15409 and CVE-2026-15410) to gain root access. The malware, including the KNUCKLEBALL loader and Java payloads (Suo5 and ORANGETAIL), facilitated the intruder's maneuvering within the network.
SonicWall has issued patches as of July 14, 2026, and CISA has included the vulnerabilities in its Known Exploited Vulnerabilities list. Organizations are advised to review appliance logs for malicious activity and ensure the vulnerabilities are addressed, as existing breaches may require more comprehensive remediation than simply applying the patch.