SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch
ID: c93c19bf-1856-5896-b555-9627e25c9658
STIX ID: report--c93c19bf-1856-5896-b555-9627e25c9658
Feed Name: CosmicBytez Labs
Threat Score
Volexity reported that threat actor UTA0533 exploited two SonicWall zero-day vulnerabilities (CVE-2026-15409 RCE and CVE-2026-15410 auth/privilege bypass) to compromise SMA and firewall appliances, deploy custom persistence malware, and perform lateral movement and data collection during a weeks-long pre-patch window; organizations are urged to apply SonicWall PSIRT patches, review management logs, audit firmware integrity, and restrict management access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
