SonicWall Security Devices Were Hacked for Weeks Before a Fix Existed

Criminals planted hidden malware inside SonicWall remote-access appliances at least three weeks before the manufacturer knew the attack routes existed. Two fresh vulnerabilities, now patched, gave intruders near-total control of the devices.

ThreatVectr Newsdesk· 3 min read
Full-frame edge-to-edge photoreal editorial shot of a server rack with a single network appliance highlighted by red status LEDs, blurred data center aisle in b
Share

Key points

  • Hackers began exploiting two previously unknown flaws in SonicWall SMA1000 appliances as early as 22 June 2025, according to cybersecurity firm Volexity.
  • SonicWall published its public security advisory on 14 July 2025, more than three weeks after exploitation is believed to have started.
  • The two flaws, CVE-2026-15409 and CVE-2026-15410, let a remote attacker break into the appliances without supplying any password.
  • The US government's Cybersecurity and Infrastructure Security Agency added both CVEs to its Known Exploited Vulnerabilities catalogue, which now lists 17 SonicWall flaws in total.
  • SonicWall has released hotfix software to close both holes; unpatched appliances remain at risk.

SonicWall makes appliances, meaning dedicated hardware boxes, that companies use to let remote workers connect securely to their internal networks. Two zero-days, meaning software flaws the manufacturer had not yet discovered or fixed, sat open in those boxes for weeks.

Volexity, the security firm that helped SonicWall investigate the attacks, says a group it calls UTA0533 was behind the break-ins. The group's identity and country of origin are unknown, but Volexity describes behaviour that looks more like a state-backed espionage operation than a straightforward criminal one.

The method was quiet and layered. Once inside, the attackers installed custom malware, that is, purpose-built malicious software, called KnuckleBall. KnuckleBall then slipped two further tools into normal, trusted processes already running on the device: a web shell called OrangeTail (a web shell is a hidden control panel that lets an attacker send commands to a machine from anywhere on the internet) and an open-source network proxy called Suo5, which can tunnel additional traffic in and out unseen.

What could the attackers actually reach?

With that level of access, quite a lot. Volexity noted that the attackers could read stored or cached login credentials, watch live network traffic passing through the appliance, and potentially intercept usernames and passwords as staff authenticated. In plain terms: a box designed to protect remote access became a front-row seat for watching everything that went through it.

The better news is narrow but real. Volexity says UTA0533 appears to have struggled to push further into the internal networks behind those appliances. Breaking into the box itself did not automatically hand them the keys to every system connected to it.

SonicWall's hotfix releases address both vulnerabilities. Organisations running SMA1000 appliances should apply the patches now, not at the next scheduled maintenance window. First reported by SecurityWeek, the advisory also confirms CISA involvement, which typically signals that federal agencies are treating the flaw as actively dangerous.

For employees at organisations that use SonicWall remote-access devices, the practical action is straightforward: if your IT team pushes a login prompt change or asks you to reset your password in the coming days, do it promptly. Credentials that passed through a compromised appliance may have been captured.

© 2026 Threat Vectr