Volexity says two SonicWall SMA1000 zero-days, CVE-2026-15409 and CVE-2026-15410, were exploited for weeks before patches were released, with activity starting as early as June 22. The attackers, tracked as UTA0533, used KnuckleBall malware to deploy the OrangeTail webshell and Suo5 proxy, prompting CISA to add the flaws to its KEV catalog. #SonicWall #UTA0533 #KnuckleBall #OrangeTail #Suo5 #CVE-2026-15409 #CVE-2026-15410
Keypoints
- Two SonicWall SMA1000 zero-days were exploited before patches were available.
- The vulnerabilities are tracked as CVE-2026-15409 and CVE-2026-15410.
- Volexity attributes the attacks to a threat actor it calls UTA0533.
- The attackers deployed KnuckleBall malware, OrangeTail, and Suo5.
- CISA added both flaws to its Known Exploited Vulnerabilities catalog.