logo

SonicWall SMA1000 flaws exploited as zero-days to push custom malware

ID: 203477fb-be40-5f0e-aeb0-603ff13632b2

STIX ID: report--203477fb-be40-5f0e-aeb0-603ff13632b2

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-07-20

Date Updated: 2026-07-21

Author: Lawrence Abrams

...
...

**Executive summary:** Volexity reports that threat actor UTA0533 exploited two zero-day SonicWall SMA1000 flaws (CVE-2026-15409 SSRF and CVE-2026-15410 command injection) to create WebSocket tunnels, retrieve device identifiers, execute commands as root, and deploy custom malware (KNUCKLEBALL deploying Sou5 and ORANGETAIL), enabling reverse-proxy and remote webshell access; SonicWall has released patches and urged immediate updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.