logo

SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch

ID: c93c19bf-1856-5896-b555-9627e25c9658

STIX ID: report--c93c19bf-1856-5896-b555-9627e25c9658

Feed Name: CosmicBytez Labs

Threat Score
88/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

...
...

Volexity reported that threat actor UTA0533 exploited two SonicWall zero-day vulnerabilities (CVE-2026-15409 RCE and CVE-2026-15410 auth/privilege bypass) to compromise SMA and firewall appliances, deploy custom persistence malware, and perform lateral movement and data collection during a weeks-long pre-patch window; organizations are urged to apply SonicWall PSIRT patches, review management logs, audit firmware integrity, and restrict management access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.