logo

SonicWall 0-day Vulnerabilities Exploited in the Wild to Deploy Custom Malware

ID: 5aa30832-ba93-5d66-9940-ee52e785c6bb

STIX ID: report--5aa30832-ba93-5d66-9940-ee52e785c6bb

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

Author: Abinaya

...
...

Volexity investigated active intrusions against SonicWall SMA 1000 series appliances in June–July 2026 where threat actor UTA0533 chained two zero-days (CVE-2026-15409 SSRF and CVE-2026-15410 command injection/path traversal) to obtain root, deploy persistent implants (ROOTRUN, KNUCKLEBALL, ORANGETAIL), capture network traffic (tcpdump), and attempt lateral movement; SonicWall issued hotfixes and Volexity published detection guidance and YARA rules.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.