logo

Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appliances

ID: d6f239c9-9750-5f33-adc1-2e14008d1b7a

STIX ID: report--d6f239c9-9750-5f33-adc1-2e14008d1b7a

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

Author: Pierluigi Paganini

...
...

Volexity uncovered an active zero-day campaign by threat actor UTA0533 that chained two SonicWall SMA1000 vulnerabilities (CVE-2026-15409 CVSS 10.0 and CVE-2026-15410 CVSS 7.2) to escalate from unauthenticated access to root, deploy custom malware (e.g., ROOTRUN, KNUCKLEBALL, ORANGETAIL), persist across reboots, and capture authentication credentials; SonicWall released patches after confirming active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.