Exploited in the wild SMA1000 secure remote access appliances UTA0533 zero-day SonicWall rce
SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch
CVE Tools coverage
Two critical zero-day vulnerabilities in SonicWall secure remote access appliances were actively exploited by a threat actor for several weeks before being patched. According to Volexity, attackers used CVE-2026-15409 and CVE-2026-15410 to deploy custom malware like KnuckleBall and gain unauthorized access to systems. SonicWall issued hotfixes on July 14 after the exploitation was discovered as early as June 22. CISA has also added these flaws to its Known Exploited Vulnerabilities catalog.