SonicWall SMA1000 flaws exploited as zero-days to push custom malware

SonicWall SMA1000 flaws exploited as zero-days to push custom malware
Two newly disclosed SonicWall SMA1000 vulnerabilities were exploited as zero-days for weeks, giving UTA0533 a path to install custom malware on VPN appliances. The attack chain used CVE-2026-15409 and CVE-2026-15410 to achieve root access and deploy KNUCKLEBALL, Sou5, ORANGETAIL, and ROOTRUN. #SonicWall #SMA1000 #CVE-2026-15409 #CVE-2026-15410 #UTA0533 #KNUCKLEBALL #Sou5 #ORANGETAIL #ROOTRUN

Keypoints

  • Two SonicWall SMA1000 flaws were abused in zero-day attacks before public disclosure.
  • CVE-2026-15409 enabled unauthenticated WebSocket tunneling through the /wsproxy endpoint.
  • CVE-2026-15410 allowed root command execution via the Appliance Management Console.
  • The attackers deployed KNUCKLEBALL to install the Sou5 and ORANGETAIL malware families.
  • The campaign also used ROOTRUN and nginx changes to extend remote access and privilege escalation.

Read More: https://www.bleepingcomputer.com/news/security/sonicwall-sma1000-flaws-exploited-as-zero-days-to-push-custom-malware/