Jessica Entwistle
July 21 2026
SecurityWeek reports that two zero-day vulnerabilities in SonicWall firewall appliances, CVE-2026-15409 and CVE-2026-15410, were exploited by a threat actor tracked as UTA0533 for several weeks before patches became available. Volexity, the security firm that discovered the activity, observed the attacker using the vulnerabilities to deliver custom malware and establish persistent access to compromised networks. The exploitation targeted SonicWall devices used for remote access and perimeter security, allowing attackers to bypass authentication and execute code on affected appliances. Patches have now been released, but organisations using affected SonicWall models face a window of exposure during which compromise may have occurred undetected.
SonicWall appliances are widely deployed across UK businesses, particularly in small to mid-sized organisations and branch office environments where they provide VPN, firewall and remote access services. The fact that exploitation occurred before patches were available means that even organisations with strong patch management disciplines could not have prevented compromise through patching alone. This creates a difficult operational reality: perimeter devices that are meant to protect the network became the entry point, and the compromise may have gone unnoticed for weeks. For many organisations, this will require forensic investigation to determine whether their devices were targeted and what level of access an attacker may have gained. The use of custom malware by the threat actor suggests a targeted campaign rather than opportunistic scanning, but the availability of exploit code means that other attackers may now attempt to exploit the same vulnerabilities. The incident highlights the operational challenge of defending against zero-day exploitation: traditional security controls such as patching cannot protect against vulnerabilities that are unknown or for which no patch exists.
Organisations using SonicWall appliances should apply the available patches immediately and review logs, access records and network traffic from the period before patches were released. Where forensic capability exists, investigating whether devices show signs of compromise is a sensible precaution, particularly if the appliances provide access to sensitive systems or data. Indicators of compromise may include unexpected configuration changes, unusual outbound network connections, new user accounts or evidence of malware deployment. For organisations without in-house forensic capability, engaging external incident response support may be appropriate where there is reason to believe compromise may have occurred. Beyond immediate remediation, this incident is a prompt to review how perimeter devices are monitored, whether anomaly detection is in place, and whether network segmentation would limit the impact of a compromised firewall. Organisations should also consider whether their security architecture places too much trust in perimeter devices and whether additional layers of defence, such as endpoint detection and response or network traffic analysis, would provide earlier warning of compromise.
Source: SecurityWeek