www.securityweek.com 7/20/2026, 2:51:42 PM · external

SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch

SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch
CyberSIXT Evidence Panel
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Available
Threat Actor
UTA0533

RECENT vulnerabilities in SonicWall appliances, identified as CVE-2026-15409 and CVE-2026-15410, were exploited by threat actor UTA0533 prior to patch releases. These vulnerabilities allowed remote, unauthenticated attacks, compromising SMA1000 secure remote access appliances through custom malware named KnuckleBall. The attackers used tools to gain root access, enabling them to capture network traffic and credentials.

Despite significant capability in compromising appliances, lateral movement to other systems was not as successful. The vulnerabilities are now included in CISA's KEV catalog.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline