View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

SonicWall SMA1000 Zero-Days Exploited to Deploy Custom Malware

🚨 ACTIVE EXPLOITATION

  • SonicWall SMA1000 Zero-Days Exploited to Deploy Custom Malware — SecurityWeek
    Threat actors exploited SonicWall SMA1000 zero-days CVE-2026-15409 and CVE-2026-15410 remotely without authentication to deliver custom malware before patches were issued.

    • Applies to SonicWall SMA1000 secure remote access appliances
    • Exploitation began around June 22, 2026, tracked by Volexity as threat actor UTA0533
    • Attackers deployed custom malware 'KnuckleBall' with Java webshell 'OrangeTail' and proxy 'Suo5'
    • Malware enabled root access to capture credentials and network traffic but showed limited lateral movement
  • Pre-authentication RCE in WordPress Core via CVE-2026-63030 and CVE-2026-60137 — Tenable
    Two chained WordPress Core vulnerabilities enable unauthenticated remote code execution on default WordPress installs without plugins.

    • Applies to WordPress Core versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1
    • CVE-2026-63030 involves REST API batch-route confusion; CVE-2026-60137 is an SQL injection in WP_Query author__not_in parameter
    • Exploitation involves crafted HTTP POST requests to the REST API batch endpoint /wp-json/batch/v1
    • Active in-the-wild exploitation and public proof-of-concept exploits appeared within days of July 17, 2026 disclosure

🕵️ RESEARCH & DEEP DIVES

🔓 CVEs & KEV

  • CVE-2026-16248 — CVSS 8.8 — Tenda AC10 stack-based overflow in AdvSetLanip fromAdvSetLanip
  • CVE-2026-64623 — CVSS 8.6 — Network-AI before 5.13.4 cryptographic signature verification bypass
  • CVE-2026-64622 — CVSS 7.5 — Network-AI 5.12.2 through 5.13.3 missing authorization via ApprovalInbox
  • CVE-2026-12080 — CVSS 7.3 — Qemu-kvm local privilege escalation via symlink attack in qemu-guest-agent
  • CVE-2026-64621 — CVSS 7.3 — FreeRDP before 3.28.0 double-free via selectedmonitors
  • Additional CVEs affecting Windu CMS, FreeRDP, and SurrealDB with various severity and impact.

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check