SonicWall 0-day Vulnerabilities Exploited in the Wild to Deploy Custom Malware
ID: 5aa30832-ba93-5d66-9940-ee52e785c6bb
STIX ID: report--5aa30832-ba93-5d66-9940-ee52e785c6bb
Feed Name: cybersecurityNews.com
Threat Score
Volexity investigated active intrusions against SonicWall SMA 1000 series appliances in June–July 2026 where threat actor UTA0533 chained two zero-days (CVE-2026-15409 SSRF and CVE-2026-15410 command injection/path traversal) to obtain root, deploy persistent implants (ROOTRUN, KNUCKLEBALL, ORANGETAIL), capture network traffic (tcpdump), and attempt lateral movement; SonicWall issued hotfixes and Volexity published detection guidance and YARA rules.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
