INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Zero-Day Exploitation in SonicWall Products
| 2026-09-11 07:11 CRITICAL HIGHExecutive Summary AI-generated
The UK Council attack is linked to a mass exploitation of SonicWall flaw CVE-2026-15409, which was rapidly weaponized and used in campaigns targeting various organizations across the globe. The vulnerability, identified as a maximum-severity SSRF (Session-Based Security Attack) flaw, allowed attackers to gain unauthorized access to critical infrastructure, including local government and law enforcement agencies, healthcare facilities, financial services providers, universities, and managed IT service providers. This widespread exploitation was facilitated by SonicWall appliances distributed across multiple countries, making it difficult for organizations to detect the underlying operating systems of these devices. The attack highlights the importance of keeping software up-to-date and implementing robust security measures to prevent similar incidents in the future.
Technical Mitigations AI-generated
* Implement a secure patching process for SonicWall appliances to ensure that all known vulnerabilities, including CVE-2026-15409, are addressed and patched before they can be exploited.
* Conduct regular security audits and vulnerability assessments of SonicWall appliances to identify potential weaknesses and implement remediation measures as soon as possible.
* Use intrusion detection and prevention systems (IDPS) that include sandboxing capabilities to detect and prevent zero-day attacks on SonicWall appliances.
* Educate users about the importance of keeping software up-to-date, using strong passwords, and being cautious when opening email attachments or clicking on links from unknown sources.
* Implement a robust incident response plan that includes procedures for responding to mass exploitation campaigns, such as those linked to CVE-2026-15409.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-83548CVE-2026-83548
CVE-2026-15409CVE-2026-15409
CVE-2026-15410CVE-2026-15410
CVE-2025-40602CVE-2025-40602
CVE-2026-83549CVE-2026-83549
Target & Sectors
FIVE_EYES
FIVE_EYES
NORTH_AMERICA
NORTH_AMERICA
healthcarehealthcare
manufacturingmanufacturing
governmentgovernment
Incident Timeline
late 2021
Ransomware attackers exploited a zero-day vulnerability in SonicWall products added to the US Cybersecurity and Infrastructure Security Agency's (CISA) Knowledge Exchange for Vulnerabilities (KEV) catalog since late 2021.
Click on any entity below to view its context and source!
tactic
Ransomware
Ten of the 19 SonicWall defects added to
CISA’s KEV catalog
since late 2021 are known to be used in ransomware campaigns.
general_metric
19 SonicWall defects
Ten of the 19 SonicWall defects added to
CISA’s KEV catalog
since late 2021 are known to be used in ransomware campaigns.
February 2025
The Five Eyes agencies provided guidance to manufacturers of edge devices designed for baseline security in February 2025.
Click on any entity below to view its context and source!
target_region
FIVE_EYES
In February 2025,
Five Eyes agencies published guidance
for manufacturers of edge devices designed to improve baseline security.
2025/09/03
Threat actors exploited a zero-day vulnerability in SonicWall products.
mid-December 2025
Threat actors exploited a recently discovered zero-day vulnerability in SonicWall SMA 1000 products.
Click on any entity below to view its context and source!
general_metric
1000 vulnerable appliances
The five defects added to CISA’s KEV most recently, since just mid-December 2025, all impact SonicWall SMA 1000 appliances.
June 22, 2026
Volexity discovered a zero-day exploit in the SonicWall SMA 1000 VPN appliances.
Click on any entity below to view its context and source!
general_metric
1000 vulnerable appliances
In July, Volexity published its findings after conducting an incident response investigation involving a compromised organization whose SonicWall SMA 1000 series VPN appliances were hit with zero-day exploits starting June 22, 2026.
organisation
SonicWall SMA 1000
In July, Volexity published its findings after conducting an incident response investigation involving a compromised organization whose SonicWall SMA 1000 series VPN appliances were hit with zero-day exploits starting June 22, 2026.
July 14
Rapid7's Managed Detection and Response team observed active exploitation of the vulnerability before SonicWall issued an advisory.
Click on any entity below to view its context and source!
organisation
Managed Detection and Response
Rapid7’s own Managed Detection and Response team had already observed active exploitation of the vulnerability before SonicWall’s July 14 advisory, meaning the gap between zero-day exploitation and mass-scale automated campaigns was effectively less than three days.
July 15
Rapid7 researchers exploited a zero-day vulnerability in SonicWall products to target Linux and Windows systems.
Click on any entity below to view its context and source!
infrastructure
Linux
“This approach could help the actor evade detection, as organisations typically have substantially less visibility into the underlying operating systems of firewall and VPN appliances than into managed Windows and Linux hosts monitored by EDR.”
Rapid7 researchers published a proof-of-concept on July 15.
infrastructure
Windows
“This approach could help the actor evade detection, as organisations typically have substantially less visibility into the underlying operating systems of firewall and VPN appliances than into managed Windows and Linux hosts monitored by EDR.”
Rapid7 researchers published a proof-of-concept on July 15.
organisation
EDR
“This approach could help the actor evade detection, as organisations typically have substantially less visibility into the underlying operating systems of firewall and VPN appliances than into managed Windows and Linux hosts monitored by EDR.”
Rapid7 researchers published a proof-of-concept on July 15.
16 July 2026
Threat actors used CVE-2026-15409 to exploit a zero-day vulnerability in SonicWall products and target SMA 1000 appliances.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-15409
By 16 July 2026, two days after SonicWall disclosed CVE-2026-15409, a threat actor was using modified, multithreaded tooling to identify vulnerable SMA 1000 appliances, extract and decrypt LDAP credentials, and automate follow-on credential theft against internal Active Directory environments.” concludes the report.
organisation
SMA
By 16 July 2026, two days after SonicWall disclosed CVE-2026-15409, a threat actor was using modified, multithreaded tooling to identify vulnerable SMA 1000 appliances, extract and decrypt LDAP credentials, and automate follow-on credential theft against internal Active Directory environments.” concludes the report.
organisation
Active Directory
By 16 July 2026, two days after SonicWall disclosed CVE-2026-15409, a threat actor was using modified, multithreaded tooling to identify vulnerable SMA 1000 appliances, extract and decrypt LDAP credentials, and automate follow-on credential theft against internal Active Directory environments.” concludes the report.
general_metric
1000 vulnerable appliances
By 16 July 2026, two days after SonicWall disclosed CVE-2026-15409, a threat actor was using modified, multithreaded tooling to identify vulnerable SMA 1000 appliances, extract and decrypt LDAP credentials, and automate follow-on credential theft against internal Active Directory environments.” concludes the report.
July 16
Threat actors used a zero-day exploit in SonicWall products to target the operator by July 16.
July 17, 2026
Threat actors exploited a zero-day vulnerability in SonicWall products to gain unauthorized access to the Borough Council of King’s Lynn's network.
Click on any entity below to view its context and source!
organisation
the Borough Council of King’s Lynn
On July 17, 2026, the Borough Council of King’s Lynn and West Norfolk announced it had detected a cyberattack affecting council services.
July 17
Threat actors used a zero-day exploit in SonicWall products to target the Hunt.io AttackCapture system on July 17.
2026/08/03
Ransomware gangs exploited two zero-day vulnerabilities in SonicWall products on or after August 3, 2026.
Click on any entity below to view its context and source!
tactic
Ransomware
Last month, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed that ransomware gangs
have begun abusing the two vulnerabilities
in the wild.
attribution
CISA
Last month, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed that ransomware gangs
have begun abusing the two vulnerabilities
in the wild.
September 1, 2026
Threat actors exploited two vulnerabilities in SonicWall SMA1000 appliances.
September 1
Threat actors exploited a zero-day vulnerability in SonicWall SMA1000 appliances, specifically models 6210, 7210 and 8200v.
Sep 02, 2026
Threat actors exploited a zero-day vulnerability in SonicWall products to gain unauthorized access.
September 02, 2026
Threat actors exploited two newly discovered zero-day vulnerabilities in SonicWall products, specifically the SMA 1000 VPNs.
Click on any entity below to view its context and source!
general_metric
1000 vulnerable appliances
SonicWall Patches Two New Actively Exploited Zero-Days in SMA 1000 VPNs
Pierluigi Paganini
September 02, 2026
SonicWall patched two zero-days in SMA 1000 VPNs, including a CVSS 10 pre-auth SSRF flaw, after confirming active exploitation.
September 11, 2026
Threat actors exploited a zero-day vulnerability in SonicWall products to target UK councils.
Click on any entity below to view its context and source!
source_region
United Kingdom
UK Council Attack Linked to Mass Exploitation of SonicWall Flaw.
UK Council Attack Linked to Mass Exploitation of SonicWall Flaw
Pierluigi Paganini
September 11, 2026
2026/09/11
Threat actors exploited a zero-day vulnerability in SonicWall's Secure Mobile Access (SMA) 1000 series VPN appliances, allowing them to execute arbitrary OS commands and gain unauthorized access to sensitive functionality.
Click on any entity below to view its context and source!
organisation
SonicWall
A critical SonicWall flaw was rapidly weaponized, with a UK Council attack linked to a campaign that exposed credentials and enabled Active Directory theft.
Attackers exploit zero-days in consistently besieged SonicWall product.
SonicWall SMA1000 vulnerabilities (CVE-2026-83548, CVE-2026-83549) in active exploitation.
Ravie Lakshmanan
Sep 02, 2026
Vulnerability / Network Security
SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks.
SonicWall Patches Two New Actively Exploited Zero-Days in SMA 1000 VPNs.
SonicWall has notified customers of two new zero-day vulnerabilities that are being exploited in the wild, one of which is a maximum-severity flaw.
SonicWall warns of actively exploited SMA1000 zero-day flaws.
organisation
SMA
Ravie Lakshmanan
Sep 02, 2026
Vulnerability / Network Security
SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks.
SonicWall has released security updates for two vulnerabilities in its SMA 1000 VPN appliances that are actively exploited in attacks in the wild.
The SMA or Secure Mobile Access appliances are gateway devices designed to enable remote workers to securely connect to corporate networks.
organisation
Vulnerability / Network Security
Ravie Lakshmanan
Sep 02, 2026
Vulnerability / Network Security
SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks.
organisation
Secure Mobile Access
Ravie Lakshmanan
Sep 02, 2026
Vulnerability / Network Security
SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks.
The SMA or Secure Mobile Access appliances are gateway devices designed to enable remote workers to securely connect to corporate networks.
organisation
KNUCKLEBALL
A separate threat actor tracked as
UTA0533
used the same vulnerability to deploy
KNUCKLEBALL
malware, and the ransomware group INC has also exploited the vulnerability chain.
The development comes more than a month after it
shipped
fixes to address two other flaws in the same product – CVE-2026-15409 (CVSS score: 10.0) and CVE-2026-15410 (CVSS score: 7.2) – that were exploited by a threat actor dubbed UTA0533 to deploy KNUCKLEBALL malware.
UTA0533
had exploited to deploy a malicious Python script named KNUCKLEBALL.
organisation
INC
A separate threat actor tracked as
UTA0533
used the same vulnerability to deploy
KNUCKLEBALL
malware, and the ransomware group INC has also exploited the vulnerability chain.
organisation
Ransomware
Ransomware groups, including INC ransomware and Akira, have taken a special interest in SonicWall.
organisation
CVSS
Hunt.io has since published a detailed technical analysis linking that incident, with moderate confidence, to a wider mass-exploitation campaign against SonicWall SMA1000 appliances using
CVE-2026-15409
, a maximum-severity SSRF flaw that received a CVSS score of 10.0.
The flaw has a CVSS score of 10.0.
organisation
CVE-2026-15409
CVE-2026-15409 affects the WorkPlace portal’s WebSocket proxy.
organisation
WorkPlace
CVE-2026-15409 affects the WorkPlace portal’s WebSocket proxy.
organisation
WebSocket
CVE-2026-15409 affects the WorkPlace portal’s WebSocket proxy.
organisation
CVE-2026
In July, two other SonicWall SMA1000 flaws (CVE-2026-15409 and CVE-2026-15410)
were exploited in zero-day attacks for weeks
to install custom malware on vulnerable VPN appliances.
The second zero day is CVE-2026-83549: a post-authentication remote code execution (RCE) vulnerability in the SMA1000 Appliance Management Console, which has a CVSS score of 7.8.
organisation
Hackers Chain Two New SonicWall Zero-Day
Hackers Chain Two New SonicWall Zero-Day Vulnerabilities.
organisation
the SMA1000 Appliance Work Place
CVE-2026-83548
is a critical (CVSS score of 10.0) unauthenticated server-side request forgery (SSRF) flaw in the SMA1000 Appliance Work Place interface.
The more critical of the two zero days is CVE-2026-83548: a pre-authentication server-side request forgery (SSRF) vulnerability in the SMA1000 Appliance Work Place interface.
infrastructure
Linux
The operator deployed a standalone Linux build of Impacket’s secretsdump directly onto selected SonicWall appliances, enabling remote credential theft from internal Windows systems.”
Once they obtain valid LDAP credentials, the attackers download a standalone Linux version of Impacket’s
secretsdump
to
/tmp/secretsdump
from their server using
curl
.
“Deploying a standalone Linux build of Impacket directly to compromised edge appliances made the operation both scalable and evasive.
Most organisations have substantially less process, file and network visibility into the underlying operating systems of security appliances than they have through EDR on managed Windows and Linux hosts.
infrastructure
Windows
The operator deployed a standalone Linux build of Impacket’s secretsdump directly onto selected SonicWall appliances, enabling remote credential theft from internal Windows systems.”
Most organisations have substantially less process, file and network visibility into the underlying operating systems of security appliances than they have through EDR on managed Windows and Linux hosts.
They then use the SonicWall appliance’s network access to run the tool against internal Windows systems and extract credentials and other sensitive information.
A SonicWall VPN appliance running
secretsdump
against internal domain controllers doesn’t trigger EDR alerts on Windows endpoints, doesn’t appear in Windows event logs as a rogue process, and doesn’t show up in most SIEM rules tuned for managed hosts.
infrastructure
12.4.3-03453
For SonicWall SMA1000 operators who haven’t patched: the fixed firmware versions are 12.4.3-03453 and later.
The flaws impact the SMA 1000 models 6210, 7210, and 8200v in the following versions -
12.4.3-03453 (platform-hotfix) and older versions
12.5.0-02835 (platform-hotfix) and older versions
Fixes have been released in versions 12.4.3-03526 (platform-hotfix) and 12.5.0-02952 (platform-hotfix).
Impacted versions are 12.4.3-03453 (platform-hotfix) and older, and 12.5.0-02835 (platform-hotfix) and older.
infrastructure
12.5.0-02835
The flaws impact the SMA 1000 models 6210, 7210, and 8200v in the following versions -
12.4.3-03453 (platform-hotfix) and older versions
12.5.0-02835 (platform-hotfix) and older versions
Fixes have been released in versions 12.4.3-03526 (platform-hotfix) and 12.5.0-02952 (platform-hotfix).
Impacted versions are 12.4.3-03453 (platform-hotfix) and older, and 12.5.0-02835 (platform-hotfix) and older.
infrastructure
12.4.3-03526
The flaws impact the SMA 1000 models 6210, 7210, and 8200v in the following versions -
12.4.3-03453 (platform-hotfix) and older versions
12.5.0-02835 (platform-hotfix) and older versions
Fixes have been released in versions 12.4.3-03526 (platform-hotfix) and 12.5.0-02952 (platform-hotfix).
12.4.3-03526 and 12.5.0-02952 versions addressed the flaws.
infrastructure
12.5.0-02952
The flaws impact the SMA 1000 models 6210, 7210, and 8200v in the following versions -
12.4.3-03453 (platform-hotfix) and older versions
12.5.0-02835 (platform-hotfix) and older versions
Fixes have been released in versions 12.4.3-03526 (platform-hotfix) and 12.5.0-02952 (platform-hotfix).
12.4.3-03526 and 12.5.0-02952 versions addressed the flaws.
organisation
Fixes
The flaws impact the SMA 1000 models 6210, 7210, and 8200v in the following versions -
12.4.3-03453 (platform-hotfix) and older versions
12.5.0-02835 (platform-hotfix) and older versions
Fixes have been released in versions 12.4.3-03526 (platform-hotfix) and 12.5.0-02952 (platform-hotfix).
organisation
IP
The SHA-256 of the Impacket binary the operator used is
690f5031deede7d3357d0ca24c89866ae8c60e6c63b3a2c8bba813a6ac10ae5b
, and the delivery IP was 95.181.173[.]36.
organisation
SonicWall SMA 1000
SonicWall customers are grappling with yet another pair of actively exploited zero-day vulnerabilities in SonicWall SMA 1000 appliances, a product that’s been besieged with recurring defects and attacks over the past nine months.
organisation
SonicWall SMA
Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain.
organisation
SMA 1000
SonicWall confirmed that the two SMA 1000 flaws are being exploited in the wild, with attackers likely chaining them to achive arbitrary code execution.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, SMA 1000)
”
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, SonicWall)
infrastructure
160 domain names
Of those, 168 exposed LDAP configuration files containing credentials for 534 Active Directory accounts across 160 domain names and 255 internal LDAP server addresses.
infrastructure
255 internal server addresses
Of those, 168 exposed LDAP configuration files containing credentials for 534 Active Directory accounts across 160 domain names and 255 internal LDAP server addresses.
organisation
SAM
Nine of those environments lost SAM and LSA secrets to the operator.
organisation
LSA
Nine of those environments lost SAM and LSA secrets to the operator.
organisation
AES
The decryption uses a fixed 32-byte AES key embedded in the
ASAPPasswordUtil.class
code.
data_breach
32 byte
The decryption uses a fixed 32-byte AES key embedded in the
ASAPPasswordUtil.class
code.
organisation
NTLM
These secrets can contain the NTLM hash of a domain controller’s machine account.
victims
250 target appliances
The campaign data covered 250 target appliances.
organisation
Appliance WorkPlace
The first is a maximum-severity command injection flaw (
CVE-2026-83548
) found in the SMA1000 Appliance WorkPlace interface that stems from a server-side request forgery (SSRF) weakness.
organisation
the Appliance Management Console
According to the SonicWall advisory, an attacker could exploit this issue to “gain unauthorized access to sensitive functionality and perform unauthorized operations.”
CVE-2026-83549
is a high-severity (CVSS score of 7.8) OS command injection vulnerability in the Appliance Management Console (AMC) that arises from improper neutralization of special elements.
CVE-2026-83549
(CVSS score: 7.8) - A post-authentication operating system command injection vulnerability in the Appliance Management Console (AMC) that could allow a remote authenticated attacker as administrator to execute arbitrary commands under specific conditions, leading to remote code execution.
CVE-2026-83549
(CVSS 7.8) is a post-authentication operating system command injection flaw in the Appliance Management Console (AMC).
organisation
AMC
According to the SonicWall advisory, an attacker could exploit this issue to “gain unauthorized access to sensitive functionality and perform unauthorized operations.”
CVE-2026-83549
is a high-severity (CVSS score of 7.8) OS command injection vulnerability in the Appliance Management Console (AMC) that arises from improper neutralization of special elements.
CVE-2026-83549
(CVSS score: 7.8) - A post-authentication operating system command injection vulnerability in the Appliance Management Console (AMC) that could allow a remote authenticated attacker as administrator to execute arbitrary commands under specific conditions, leading to remote code execution.
CVE-2026-83549
(CVSS 7.8) is a post-authentication operating system command injection flaw in the Appliance Management Console (AMC).
organisation
CVE-2026-83549
CVE-2026-83549
(CVSS score: 7.8) - A post-authentication operating system command injection vulnerability in the Appliance Management Console (AMC) that could allow a remote authenticated attacker as administrator to execute arbitrary commands under specific conditions, leading to remote code execution.
CVE-2026-83549
(CVSS 7.8) is a post-authentication operating system command injection flaw in the Appliance Management Console (AMC).
organisation
the SMA1000 Appliance Management Console
The second zero day is CVE-2026-83549: a post-authentication remote code execution (RCE) vulnerability in the SMA1000 Appliance Management Console, which has a CVSS score of 7.8.
This actively exploited zero-day chain also targets a command injection vulnerability (
CVE-2026-83549
) in the SMA1000 Appliance Management Console that attackers with admin privileges can exploit to execute arbitrary OS commands on vulnerable devices.
organisation
KEV
The Cybersecurity and Infrastructure Security Agency added the defects to its
known exploited vulnerabilities (KEV) catalog
Wednesday.
organisation
Huntress
In late July, Huntress researchers spotted an attack spree that
compromised 30 SonicWall customers
in less than two days.
victims
30 SonicWall customers
In late July, Huntress researchers spotted an attack spree that
compromised 30 SonicWall customers
in less than two days.
organisation
Counter Threat Unit
Recommended actions
Counter Threat Unit™ (CTU) researchers recommend that organizations identify vulnerable SonicWall appliances in their environments and upgrade as appropriate as soon as possible.
organisation
Contact SonicWall Technical Support
It said
they should:
Upgrade to the latest hotfix version
Contact SonicWall Technical Support for assistance in looking for indicators of compromise (IoCs)
organisation
SSL
The two security flaws affect SMA1000 6210, 7210, and 8200v models, but they don't affect SSL-VPN running on SonicWall firewalls or the SMA 100 Series product line.
organisation
The Blue Report 2026
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Tactical Metrics
Metrics
infrastructure
Linux
Affected Product
Click for context!
The operator deployed a standalone Linux build of Impacket’s secretsdump directly onto selected SonicWall appliances, enabling remote credential theft from internal Windows systems.”
“This approach could help the actor evade detection, as organisations typically have substantially less visibility into the underlying operating systems of firewall and VPN appliances than into managed Windows and Linux hosts monitored by EDR.”
Rapid7 researchers published a proof-of-concept on July 15.
Once they obtain valid LDAP credentials, the attackers download a standalone Linux version of Impacket’s
secretsdump
to
/tmp/secretsdump
from their server using
curl
.
“Deploying a standalone Linux build of Impacket directly to compromised edge appliances made the operation both scalable and evasive.
Most organisations have substantially less process, file and network visibility into the underlying operating systems of security appliances than they have through EDR on managed Windows and Linux hosts.
Metrics
infrastructure
Windows
Affected Product
The operator deployed a standalone Linux build of Impacket’s secretsdump directly onto selected SonicWall appliances, enabling remote credential theft from internal Windows systems.”
“This approach could help the actor evade detection, as organisations typically have substantially less visibility into the underlying operating systems of firewall and VPN appliances than into managed Windows and Linux hosts monitored by EDR.”
Rapid7 researchers published a proof-of-concept on July 15.
They then use the SonicWall appliance’s network access to run the tool against internal Windows systems and extract credentials and other sensitive information.
A SonicWall VPN appliance running
secretsdump
against internal domain controllers doesn’t trigger EDR alerts on Windows endpoints, doesn’t appear in Windows event logs as a rogue process, and doesn’t show up in most SIEM rules tuned for managed hosts.
Most organisations have substantially less process, file and network visibility into the underlying operating systems of security appliances than they have through EDR on managed Windows and Linux hosts.
Metrics
infrastructure
12.4.3-03453
Software Version
For SonicWall SMA1000 operators who haven’t patched: the fixed firmware versions are 12.4.3-03453 and later.
The flaws impact the SMA 1000 models 6210, 7210, and 8200v in the following versions -
12.4.3-03453 (platform-hotfix) and older versions
12.5.0-02835 (platform-hotfix) and older versions
Fixes have been released in versions 12.4.3-03526 (platform-hotfix) and 12.5.0-02952 (platform-hotfix).
Impacted versions are 12.4.3-03453 (platform-hotfix) and older, and 12.5.0-02835 (platform-hotfix) and older.
Metrics
infrastructure
160
Domain Names
Of those, 168 exposed LDAP configuration files containing credentials for 534 Active Directory accounts across 160 domain names and 255 internal LDAP server addresses.
Metrics
infrastructure
255
Internal Server Addresses
Of those, 168 exposed LDAP configuration files containing credentials for 534 Active Directory accounts across 160 domain names and 255 internal LDAP server addresses.
Metrics
data_breach
32
Byte
The decryption uses a fixed 32-byte AES key embedded in the
ASAPPasswordUtil.class
code.
Metrics
victims
250
Target Appliances
The campaign data covered 250 target appliances.
Metrics
victims
30
Sonicwall Customers
In late July, Huntress researchers spotted an attack spree that
compromised 30 SonicWall customers
in less than two days.
Metrics
infrastructure
12.5.0-02835
Software Version
The flaws impact the SMA 1000 models 6210, 7210, and 8200v in the following versions -
12.4.3-03453 (platform-hotfix) and older versions
12.5.0-02835 (platform-hotfix) and older versions
Fixes have been released in versions 12.4.3-03526 (platform-hotfix) and 12.5.0-02952 (platform-hotfix).
Impacted versions are 12.4.3-03453 (platform-hotfix) and older, and 12.5.0-02835 (platform-hotfix) and older.
Metrics
infrastructure
12.4.3-03526
Software Version
The flaws impact the SMA 1000 models 6210, 7210, and 8200v in the following versions -
12.4.3-03453 (platform-hotfix) and older versions
12.5.0-02835 (platform-hotfix) and older versions
Fixes have been released in versions 12.4.3-03526 (platform-hotfix) and 12.5.0-02952 (platform-hotfix).
12.4.3-03526 and 12.5.0-02952 versions addressed the flaws.
Metrics
infrastructure
12.5.0-02952
Software Version
The flaws impact the SMA 1000 models 6210, 7210, and 8200v in the following versions -
12.4.3-03453 (platform-hotfix) and older versions
12.5.0-02835 (platform-hotfix) and older versions
Fixes have been released in versions 12.4.3-03526 (platform-hotfix) and 12.5.0-02952 (platform-hotfix).
12.4.3-03526 and 12.5.0-02952 versions addressed the flaws.
Intelligence Sources
Infosecurity-Magazine
2026-09-02
Hackers Chain Two New SonicWall Zero-Day Vulnerabilities
Infosecurity-Magazine
BleepingComputer
2026-09-02
SonicWall warns of actively exploited SMA1000 zero-day flaws
BleepingComputer
Sophos News
2026-09-02
Security Affairs
2026-09-02
The Hacker News
2026-09-02
CyberScoop
2026-09-03
Security Affairs
2026-09-11
UK Council Attack Linked to Mass Exploitation of SonicWall Flaw
Security Affairs
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-09-11T10:31
Comprehensive Tactical Telemetry
Highly Correlated Entities
41x
organisation
Identified Entity
SonicWall
entity
20x
timeline
Temporal Reference
September 11, 2026
date
11x
source region
Origin Country
United Kingdom
country
5x
vulnerability
Exploited CVE
CVE-2026-15409
cve
4x
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
4x
infrastructure
Software Version
12.4.3-03453
version
3x
industry
Targeted Sector
Government
sector
3x
attribution
Attributing Entity
CISA
authority
3x
vulnerability
CVSS Score
10
score
2x
target region
Target Country
Hong Kong
country
2x
tactic
Cyber Operation Type
Ransomware
tactic
2x
infrastructure
Affected Product
Linux
software
Contextual Telemetry
Context Block
22 METRICS
general metric
Vulnerable Appliances
1,000
vulnerable appliances
general metric
Entities
168
entities
general metric
Active Directory
534
active directory
infrastructure
Domain Names
160
domain names
infrastructure
Internal Server Addresses
255
internal server addresses
data breach
Byte
32
byte
victims
Target Appliances
250
target appliances
general metric
Addresses
200,000
addresses
general metric
Port
80
port
general metric
Sonicwall Defects
19
sonicwall defects
victims
Sonicwall Customers
30
sonicwall customers
general metric
Cve-2026 83549
8
cve-2026 83549
general metric
Models
6,210
models
general metric
Hotfix
2,952
hotfix
general metric
Score
7
score
general metric
Sep
2
sep
general metric
Versions
3,526
versions
target region
Target Region
FIVE_EYES
region
general metric
Sma
100
sma
general metric
Blue Report
2,026
blue report
general metric
Simulations
338,000,000
simulations
general metric
Sma1000 Appliances
400
sma1000 appliances
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.