Exploitation of two SonicWall zero-day vulnerabilities, CVE-2026-15409 and CVE-2026-15410, was carried out by the UTA0533 threat actor for several weeks prior to the release of a patch. This allowed the attacker to deliver customized malware to targeted systems, expanding the active attack surface for affected organizations. The vulnerabilities were exploited to gain unauthorized access, highlighting the importance of prompt patching and vulnerability management. The fact that these zero-days were exploited for an extended period before a patch was available1 underscores the need for organizations to prioritize their exposure and take proactive measures to mitigate potential attacks. This incident serves as a reminder that timely patching and continuous monitoring are crucial in preventing and detecting such attacks, so what matters most to practitioners is the immediate assessment of their exposure to these vulnerabilities and taking swift action to remediate them.
SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch
⚠️ Critical Alert
Why This Matters
CVE-2026-15409 disclosure expands the active attack surface — prioritize based on your exposure and exploitation evidence.
References
- SecurityWeek. (2026, July 20). SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch. SecurityWeek. https://www.securityweek.com/sonicwall-zero-days-exploited-to-deliver-custom-malware-for-weeks-before-patch/
Original Source
SecurityWeek
Read original →