Two recently patched SonicWall appliance zero-days were exploited by threat actors for weeks before patches were released, according to cybersecurity firm Volexity.
SonicWall released a public advisory for the vulnerabilities on July 14, informing customers that CVE-2026-15409 and CVE-2026-15410 had been exploited in the wild.
Remote, unauthenticated attackers can exploit the flaws to hack SMA1000 secure remote access appliances. SonicWall has made available hotfix releases to address the security holes.
Volexity, which assisted the vendor’s investigation into the attacks, attributed the exploitation of the zero-days to a threat actor it tracks as UTA0533.
The security firm believes exploitation started as early as June 22.
The company on Friday shared IoCs and other technical details related to the attacks, but it has not linked UTA0533 to any known threat actor and the group’s motivation remains unclear. However, based on Volexity’s description, the attack appears more consistent with state-sponsored APT activity rather than a profit-driven cybercrime operation.
Once the attackers compromised the targeted SonicWall appliances, they deployed custom malware named KnuckleBall, which injected two other tools into legitimate processes: a tailored Java webshell named OrangeTail, and an open source proxy named Suo5.
“With root access, the threat actor could access stored or cached credentials, capture network traffic, and potentially intercept credentials processed by the appliances,” Volexity said.
The security firm added, “Although UTA0533 demonstrated significant capability in compromising the SonicWall appliances, available evidence suggests the threat actor was less successful moving laterally or gaining access to other systems.”
CISA has added CVE-2026-15409 and CVE-2026-15410 to its KEV catalog, which currently includes 17 flaws affecting SonicWall products.
Related: WP2Shell WordPress Vulnerabilities Exploited in the Wild
Related: Fresh SharePoint Vulnerability Exploited Soon After Disclosure
Related: Splunk, Zoom Patch Critical Vulnerabilities
Related: Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day

