#4
BleepingComputer
general
July 20, 2026 at 22:23 UTC
SonicWall SMA1000 flaws exploited as zero-days to push custom malware
By Lawrence Abrams
AI Summary
Two SonicWall SMA1000 zero-days — CVE-2026-15409 and CVE-2026-15410 — were exploited for weeks before patches were available by threat actor UTA0533 (tracked by Volexity), who installed custom malware on vulnerable VPN appliances. Pre-patch exploitation of VPN appliances for custom implant delivery represents a high-impact supply chain risk for enterprise network perimeters.
Relevance score: 88.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →