Two newly disclosed SonicWall SMA1000 vulnerabilities were exploited as zero-days for weeks, giving UTA0533 a path to install custom malware on VPN appliances. The attack chain used CVE-2026-15409 and CVE-2026-15410 to achieve root access and deploy KNUCKLEBALL, Sou5, ORANGETAIL, and ROOTRUN. #SonicWall #SMA1000 #CVE-2026-15409 #CVE-2026-15410 #UTA0533 #KNUCKLEBALL #Sou5 #ORANGETAIL #ROOTRUN
Keypoints
- Two SonicWall SMA1000 flaws were abused in zero-day attacks before public disclosure.
- CVE-2026-15409 enabled unauthenticated WebSocket tunneling through the /wsproxy endpoint.
- CVE-2026-15410 allowed root command execution via the Appliance Management Console.
- The attackers deployed KNUCKLEBALL to install the Sou5 and ORANGETAIL malware families.
- The campaign also used ROOTRUN and nginx changes to extend remote access and privilege escalation.