Exploited in the wild SMA1000 Secure Mobile Access appliances UTA0533 malware SonicWall network-edge
SonicWall SMA1000 flaws exploited as zero-days to push custom malware
CVE Tools coverage
Threat actors have exploited two zero-day vulnerabilities in SonicWall SMA1000 Secure Mobile Access appliances—CVE-2026-15409 and CVE-2026-15410—to install custom malware on vulnerable systems. These flaws allowed attackers to bypass authentication, gain root access, and deploy malicious tools like KNUCKLEBALL, Sou5, and ORANGETAIL. Security firm Volexity uncovered the attack chain, revealing that the threat actor, tracked as UTA0533, began exploiting these issues as early as June 22, weeks before public disclosure. SonicWall has issued patches for versions 6210, 7210, and 8200v; users are urged to apply them immediately.