SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch
Overview
SonicWall discovered that two zero-day vulnerabilities, identified as CVE-2026-15409 and CVE-2026-15410, were exploited by a threat actor known as UTA0533. These vulnerabilities were actively used to deliver custom malware over several weeks before a patch was released. Organizations using affected SonicWall products need to be particularly vigilant, as the malware has already been deployed in the wild. This situation emphasizes the importance of timely patch management and monitoring for unusual activity, given that attackers can exploit such vulnerabilities to gain unauthorized access to systems. Companies should prioritize updating their security infrastructure to mitigate the risk posed by these exploits.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: SonicWall products affected by CVE-2026-15409 and CVE-2026-15410
- Action Required: SonicWall has released patches for CVE-2026-15409 and CVE-2026-15410.
- Timeline: Newly disclosed
Original Article Summary
The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533. The post SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch appeared first on SecurityWeek.
Impact
SonicWall products affected by CVE-2026-15409 and CVE-2026-15410
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
SonicWall has released patches for CVE-2026-15409 and CVE-2026-15410. Users are advised to update their systems immediately to the latest version to mitigate the vulnerabilities.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to CVE, Zero-day, Exploit, and 3 more.