RECENT vulnerabilities in SonicWall appliances, identified as CVE-2026-15409 and CVE-2026-15410, were exploited by threat actor UTA0533 prior to patch releases. These vulnerabilities allowed remote, unauthenticated attacks, compromising SMA1000 secure remote access appliances through custom malware named KnuckleBall. The attackers used tools to gain root access, enabling them to capture network traffic and credentials.
Despite significant capability in compromising appliances, lateral movement to other systems was not as successful. The vulnerabilities are now included in CISA's KEV catalog.