SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch
Summary
Two zero-day vulnerabilities in SonicWall products, CVE-2026-15409 and CVE-2026-15410, were actively exploited by a threat actor known as UTA0533 to deliver custom malware. These exploits were in the wild for several weeks before SonicWall released patches for the affected devices.
IFF Assessment
The active exploitation of zero-day vulnerabilities to deploy malware represents a direct threat to organizations using the affected SonicWall products.
Severity
The CVSS score is estimated to be high due to the critical nature of zero-day vulnerabilities, potential for remote code execution, and the fact that they were actively exploited before a patch was available, suggesting a high degree of exploitability and impact.
CISA KEV: Listed as actively exploited. Federal patch due: July 17, 2026. Known ransomware use: Unknown.
Defender Context
This incident highlights the critical need for organizations to promptly apply security patches, especially for hardware and software used in network perimeters. Defenders should monitor for indicators of compromise related to SonicWall devices and be aware of threat actors actively exploiting unpatched vulnerabilities.