ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
CRITICAL Vulnerabilities

SonicWall Zero-Day Flaws CVE-2026-15409/15410 Used to Drop Malware

Source headline: SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch

Threat level Critical
Signal strength 80/100
Source confidence 1 source
Published 13 hours ago

Intelligence Summary

A threat actor exploited SonicWall vulnerabilities CVE-2026-15409 and CVE-2026-15410 to deliver custom malware. Volexity tracks the activity as UTA0533. The exploitation is reported to have continued for weeks before a patch was available. Organizations using affected SonicWall appliances were exposed to remote compromise and follow-on malware deployment. Administrators should check for available SonicWall updates and apply mitigations immediately.

Recommended Action

Prioritize immediate review, validate exposure, and patch or mitigate affected systems.

Topics

#malware #zeroday #sonicwall #cve-2026-15409 #cve-2026-15410 #network-appliance #volextiy-uta0533
Original reporting SecurityWeek SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch
Open original source