Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appliances
ID: d6f239c9-9750-5f33-adc1-2e14008d1b7a
STIX ID: report--d6f239c9-9750-5f33-adc1-2e14008d1b7a
Feed Name: Security Affairs
Threat Score
Volexity uncovered an active zero-day campaign by threat actor UTA0533 that chained two SonicWall SMA1000 vulnerabilities (CVE-2026-15409 CVSS 10.0 and CVE-2026-15410 CVSS 7.2) to escalate from unauthenticated access to root, deploy custom malware (e.g., ROOTRUN, KNUCKLEBALL, ORANGETAIL), persist across reboots, and capture authentication credentials; SonicWall released patches after confirming active exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
