INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Zero-Day Exploitation in SonicWall Products

| 2026-09-11 07:11 CRITICAL HIGH
Executive Summary AI-generated
The UK Council attack is linked to a mass exploitation of SonicWall flaw CVE-2026-15409, which was rapidly weaponized and used in campaigns targeting various organizations across the globe. The vulnerability, identified as a maximum-severity SSRF (Session-Based Security Attack) flaw, allowed attackers to gain unauthorized access to critical infrastructure, including local government and law enforcement agencies, healthcare facilities, financial services providers, universities, and managed IT service providers. This widespread exploitation was facilitated by SonicWall appliances distributed across multiple countries, making it difficult for organizations to detect the underlying operating systems of these devices. The attack highlights the importance of keeping software up-to-date and implementing robust security measures to prevent similar incidents in the future.
Technical Mitigations AI-generated
* Implement a secure patching process for SonicWall appliances to ensure that all known vulnerabilities, including CVE-2026-15409, are addressed and patched before they can be exploited. * Conduct regular security audits and vulnerability assessments of SonicWall appliances to identify potential weaknesses and implement remediation measures as soon as possible. * Use intrusion detection and prevention systems (IDPS) that include sandboxing capabilities to detect and prevent zero-day attacks on SonicWall appliances. * Educate users about the importance of keeping software up-to-date, using strong passwords, and being cautious when opening email attachments or clicking on links from unknown sources. * Implement a robust incident response plan that includes procedures for responding to mass exploitation campaigns, such as those linked to CVE-2026-15409.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-83548CVE-2026-83548 CVE-2026-15409CVE-2026-15409 CVE-2026-15410CVE-2026-15410 CVE-2025-40602CVE-2025-40602 CVE-2026-83549CVE-2026-83549
Target & Sectors
FIVE_EYES FIVE_EYES NORTH_AMERICA NORTH_AMERICA healthcarehealthcare manufacturingmanufacturing governmentgovernment
Incident Timeline
‎late 2021
Ransomware attackers exploited a zero-day vulnerability in SonicWall products added to the US Cybersecurity and Infrastructure Security Agency's (CISA) Knowledge Exchange for Vulnerabilities (KEV) catalog since late 2021.
tactic Ransomware
general_metric 19 SonicWall defects
‎February 2025
The Five Eyes agencies provided guidance to manufacturers of edge devices designed for baseline security in February 2025.
target_region FIVE_EYES
‎2025/09/03
Threat actors exploited a zero-day vulnerability in SonicWall products.
‎mid-December 2025
Threat actors exploited a recently discovered zero-day vulnerability in SonicWall SMA 1000 products.
general_metric 1000 vulnerable appliances
‎June 22, 2026
Volexity discovered a zero-day exploit in the SonicWall SMA 1000 VPN appliances.
general_metric 1000 vulnerable appliances
organisation SonicWall SMA 1000
‎July 14
Rapid7's Managed Detection and Response team observed active exploitation of the vulnerability before SonicWall issued an advisory.
organisation Managed Detection and Response
‎July 15
Rapid7 researchers exploited a zero-day vulnerability in SonicWall products to target Linux and Windows systems.
infrastructure Linux
infrastructure Windows
organisation EDR
‎16 July 2026
Threat actors used CVE-2026-15409 to exploit a zero-day vulnerability in SonicWall products and target SMA 1000 appliances.
vulnerability CVE-2026-15409
organisation SMA
organisation Active Directory
general_metric 1000 vulnerable appliances
‎July 16
Threat actors used a zero-day exploit in SonicWall products to target the operator by July 16.
‎July 17, 2026
Threat actors exploited a zero-day vulnerability in SonicWall products to gain unauthorized access to the Borough Council of King’s Lynn's network.
organisation the Borough Council of King’s Lynn
‎July 17
Threat actors used a zero-day exploit in SonicWall products to target the Hunt.io AttackCapture system on July 17.
‎2026/08/03
Ransomware gangs exploited two zero-day vulnerabilities in SonicWall products on or after August 3, 2026.
tactic Ransomware
attribution CISA
‎September 1, 2026
Threat actors exploited two vulnerabilities in SonicWall SMA1000 appliances.
‎September 1
Threat actors exploited a zero-day vulnerability in SonicWall SMA1000 appliances, specifically models 6210, 7210 and 8200v.
‎Sep 02, 2026
Threat actors exploited a zero-day vulnerability in SonicWall products to gain unauthorized access.
‎September 02, 2026
Threat actors exploited two newly discovered zero-day vulnerabilities in SonicWall products, specifically the SMA 1000 VPNs.
general_metric 1000 vulnerable appliances
‎September 11, 2026
Threat actors exploited a zero-day vulnerability in SonicWall products to target UK councils.
source_region United Kingdom
‎2026/09/11
Threat actors exploited a zero-day vulnerability in SonicWall's Secure Mobile Access (SMA) 1000 series VPN appliances, allowing them to execute arbitrary OS commands and gain unauthorized access to sensitive functionality.
organisation SonicWall
organisation SMA
organisation Vulnerability / Network Security
organisation Secure Mobile Access
organisation KNUCKLEBALL
organisation INC
organisation Ransomware
organisation CVSS
organisation CVE-2026-15409
organisation WorkPlace
organisation WebSocket
organisation CVE-2026
organisation Hackers Chain Two New SonicWall Zero-Day
organisation the SMA1000 Appliance Work Place
infrastructure Linux
infrastructure Windows
infrastructure 12.4.3-03453
infrastructure 12.5.0-02835
infrastructure 12.4.3-03526
infrastructure 12.5.0-02952
organisation Fixes
organisation IP
organisation SonicWall SMA 1000
organisation SonicWall SMA
organisation SMA 1000
organisation SecurityAffairs
infrastructure 160 domain names
infrastructure 255 internal server addresses
organisation SAM
organisation LSA
organisation AES
data_breach 32 byte
organisation NTLM
victims 250 target appliances
organisation Appliance WorkPlace
organisation the Appliance Management Console
organisation AMC
organisation CVE-2026-83549
organisation the SMA1000 Appliance Management Console
organisation KEV
organisation Huntress
victims 30 SonicWall customers
organisation Counter Threat Unit
organisation Contact SonicWall Technical Support
organisation SSL
organisation The Blue Report 2026
Tactical Metrics
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎12.4.3-03453
Software Version
Metrics
infrastructure
160
Domain Names
Metrics
infrastructure
255
Internal Server Addresses
Metrics
data_breach
32
Byte
Metrics
victims
250
Target Appliances
Metrics
victims
30
Sonicwall Customers
Metrics
infrastructure
‎12.5.0-02835
Software Version
Metrics
infrastructure
‎12.4.3-03526
Software Version
Metrics
infrastructure
‎12.5.0-02952
Software Version