Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

1989+ Articles
151+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch
SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch
NEWS

SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch

Threat actor UTA0533 exploited two SonicWall zero-day vulnerabilities — CVE-2026-15409 and CVE-2026-15410 — to deploy custom malware against targets weeks before patches became available.

Dylan H.

News Desk

July 20, 2026
4 min read

Two SonicWall zero-day vulnerabilities were actively exploited in the wild to deliver custom malware against organizational targets for weeks before patches were made available, according to research from Volexity. The threat actor behind the campaign, tracked as UTA0533, targeted SonicWall network appliances using the flaws CVE-2026-15409 and CVE-2026-15410.

What Happened

Volexity researchers identified an active exploitation campaign targeting SonicWall SMA (Secure Mobile Access) and firewall appliances. The attackers leveraged two previously unknown vulnerabilities to gain initial access to victim networks, then deployed custom malware specifically developed for the campaign — indicating a sophisticated, resource-rich threat actor.

The exploitation window — spanning weeks before SonicWall could develop and release patches — allowed UTA0533 significant dwell time within victim environments, enabling:

  • Initial access via the SonicWall perimeter appliance
  • Custom malware deployment to establish persistent footholds
  • Lateral movement into internal networks using the trusted network position of the firewall appliance
  • Data collection and exfiltration during the pre-patch window

The Vulnerabilities

CVETypeAffected Products
CVE-2026-15409Remote Code ExecutionSonicWall SMA / Firewall appliances
CVE-2026-15410Authentication Bypass / Privilege EscalationSonicWall SMA / Firewall appliances

Full technical details of the flaws have been withheld or partially disclosed pending broader patch adoption, a common practice to limit exploitation during the patch deployment window.

Threat Actor: UTA0533

Volexity tracks UTA0533 as a sophisticated threat group with characteristics consistent with nation-state or advanced criminal operations. The development of custom malware tailored to SonicWall's platform architecture — rather than relying on off-the-shelf tools — is a strong indicator of significant pre-attack investment and knowledge of the target platform.

Custom malware of this type is typically designed to:

  • Evade standard detection tooling that signatures commercial or open-source malware families
  • Persist across firmware updates or reboots of the affected appliance
  • Blend with legitimate traffic on the network perimeter device

Why Perimeter Devices Are Prime Targets

SonicWall firewalls and SMA appliances sit at the network perimeter with:

  • High inherent trust — network traffic flows through them
  • Broad internal network access — ideal pivot points for lateral movement
  • Infrequent security monitoring — organizations rarely deploy EDR or detailed logging on appliances
  • Slow patch cycles — firmware updates require maintenance windows, delaying remediation

This pattern — zero-days targeting perimeter security appliances — has been a dominant attack vector in recent years, seen against Fortinet, Ivanti, Palo Alto Networks, and now SonicWall again.

Indicators and Detection

Organizations running SonicWall appliances should:

  1. Apply available patches immediately — SonicWall has released firmware updates addressing both CVEs
  2. Review SonicWall management interface access logs for anomalous authentication patterns pre-patch
  3. Look for unexpected outbound connections from firewall management interfaces
  4. Audit firmware integrity — verify appliance firmware has not been modified
  5. Check for new or modified administrator accounts on affected appliances
# SonicWall log review examples (from management console or syslog)
# Look for:
# - Authentication from unexpected source IPs
# - API calls outside business hours
# - Firmware access or modification events
# - Unusual management plane traffic

Patch and Mitigation Guidance

ActionPriority
Apply SonicWall patches for CVE-2026-15409 and CVE-2026-15410Critical — immediately
Restrict SonicWall management interface to trusted IPs onlyHigh
Enable multi-factor authentication on SonicWall managementHigh
Review and rotate VPN user credentialsMedium
Audit for persistence mechanisms on patched appliancesHigh

SonicWall has published security advisories for both CVEs through its Product Security Incident Response Team (PSIRT). Organizations should consult the official SonicWall PSIRT portal for firmware versions and patch guidance specific to their appliance model.

Broader Trend: Pre-Patch Zero-Day Windows

This incident reinforces a disturbing trend in enterprise security: sophisticated threat actors increasingly target perimeter network security devices with zero-day exploits, exploiting the gap between vulnerability discovery and patch availability. The weeks-long exploitation window before patching highlights the importance of:

  • Network segmentation that limits the blast radius even if a perimeter device is compromised
  • Zero-trust architecture that does not grant implicit trust based on network position
  • Continuous monitoring of perimeter device behavior, not just internal endpoints

References

  • SecurityWeek — SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch
  • Volexity Research
  • SonicWall PSIRT
#Malware#Zero-Day#CVE#SonicWall#UTA0533#Threat Intelligence

Related Articles

SonicWall SMA1000 Flaws Exploited as Zero-Days to Push Custom Malware

Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks before patches were available, allowing threat actors to install custom malware implants on vulnerable enterprise VPN appliances.

6 min read

Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More

A single request shouldn't be able to do this much. This week delivered pre-authenticated WordPress RCE, dual SonicWall zero-days exploited since June, a CVSS 9.8 SharePoint deserialization flaw, and a botnet actively targeting exposed AI services like ComfyUI, Ollama, and n8n.

4 min read

Interlock Ransomware Has Been Exploiting Cisco FMC Zero-Day

The Interlock ransomware gang has been actively exploiting a CVSS 10.0 insecure deserialization flaw in Cisco Secure Firewall Management Center since late...

7 min read
Back to all News