Vendor
Multiple Vulnerabilities in SonicWall Network Security Manager
SonicWall Network Security Manager (NSM) versions prior to 4.3.1-R4 contain multiple vulnerabilities, including CVE-2026-78327, CVE-2026-78328, and CVE-2026-81939, that allow for remote code execution, privilege escalation, and security policy bypass.
Critical SSRF Vulnerability in SonicWall SMA1000 Appliances
1 TTP 2 CVEsSonicWall SMA1000 appliances are vulnerable to an unauthenticated server-side request forgery (SSRF) flaw, enabling remote attackers to access sensitive internal functionality and perform unauthorized operations.
Active Exploitation of SonicWall SMA 1000 Series Appliances
2 TTPs 2 CVEsSonicWall has addressed two actively exploited vulnerabilities, CVE-2024-5091 and CVE-2024-5092, in the SMA 1000 series that allow for unauthenticated unauthorized actions and authenticated command execution.
Security Policy Bypass Vulnerabilities in SonicWall NetExtender
2 CVEsMultiple vulnerabilities, CVE-2026-66152 and CVE-2026-66153, in SonicWall NetExtender Linux Client versions prior to 10.3.6 allow attackers to bypass security policy enforcement.
Detection of Anomalous SonicWall Remote Access Logins
1 rule 2 TTPsThis detection logic identifies potentially unauthorized remote or administrative VPN access by monitoring for successful login combinations of user, source IP, and appliance not observed in the previous 14 days.
Akira Ransomware Affiliate Abuses Safe Mode to Evade EDR
1 rule 2 TTPs 3 IOCsAn Akira ransomware affiliate gained initial access via a SonicWall VPN and attempted to evade security controls by rebooting the host into Safe Mode, an anti-EDR tactic that ultimately caused the ransomware to crash.
Multiple Vulnerabilities in SonicWall Global Management System
2 TTPsMultiple vulnerabilities in SonicWall Global Management System (GMS) present risks for remote code execution by unauthenticated attackers.
Multiple Vulnerabilities in SonicWall GMS
3 TTPsSonicWall GMS contains multiple vulnerabilities allowing remote code execution with root privileges, privilege escalation, security bypass, and information disclosure.
Multiple Vulnerabilities in SonicWall Email Security
1 TTPSonicWall Email Security contains multiple local vulnerabilities that permit an attacker to execute arbitrary code with administrative privileges, leading to full appliance compromise.
Active Exploitation of SonicWall SMA 1000 Series Appliances by Ransomware Actors
1 TTP 1 CVECISA has added CVE-2024-40766 to its Known Exploited Vulnerabilities catalog after reports that ransomware actors are leveraging the flaw in SonicWall SMA 1000 series appliances to gain initial access to enterprise networks.
Denial of Service Vulnerability in SonicWall Global VPN Client
1 TTP 1 CVEA vulnerability (CVE-2026-66151) in SonicWall Global VPN Client versions prior to 5.0.0.2008 allows remote attackers to trigger a denial of service condition.
Security Policy Bypass in SonicWall SonicOS
1 CVEA security policy bypass vulnerability (CVE-2026-0516) in SonicWall SonicOS affects multiple hardware generations and virtual appliances, potentially allowing unauthorized access or configuration subversion.
CVE-2026-63030: Critical Remote Code Execution Vulnerability in WordPress Core
2 TTPs 15 CVEs 8 IOCsCVE-2026-63030 is a critical unauthenticated remote code execution vulnerability affecting WordPress Core versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1, allowing an unauthenticated attacker to execute arbitrary code via the WordPress REST API batch endpoint, potentially leading to complete website compromise.
SonicWall SMA: Multiple Vulnerabilities
3 TTPsMultiple vulnerabilities in SonicWall SMA allow an unauthenticated, remote attacker to bypass security mechanisms and execute arbitrary operating system commands on the affected system, leading to full compromise of the appliance.
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability (CVE-2026-15409)
2 TTPs 2 CVEs 6 IOCsA critical server-side request forgery (SSRF) vulnerability, identified as CVE-2026-15409, exists in SonicWall SMA1000 Appliances, allowing a remote, unauthenticated attacker to force the appliance to make requests to arbitrary internal or external locations, potentially leading to information disclosure or access to restricted network services.
Plain Text Passwords: A Direct Path to Organizational Compromise
2 rules 4 TTPs 2 IOCsA threat actor, after gaining initial access via a SonicWall VPN vulnerability, exploited plain text Huntress portal recovery codes found on a security engineer's desktop to infiltrate the security platform, enabling defense evasion and furthering malicious activity.
SonicWall Gen6 SSL-VPN MFA Bypass via CVE-2024-12802
2 rules 1 TTP 1 CVEThreat actors exploited CVE-2024-12802, a vulnerability in SonicWall Gen6 SSL-VPN appliances, to bypass multi-factor authentication (MFA) after brute-forcing VPN credentials, leading to the deployment of ransomware-related tools.
Ransomware-as-a-Service (RaaS) Ecosystem: Affiliate Tradecraft and Initial Access Vectors
2 rules 1 TTPRansomware-as-a-service (RaaS) attacks leverage affiliates for initial access, persistence, and exfiltration, using varied techniques like compromised RDP, vulnerable VPNs, and rogue RMM tools, impacting multiple organizations in a single campaign.
Multiple Vulnerabilities in SonicWall Firewalls Allow Remote Code Execution and Privilege Escalation
1 rule 3 TTPs 4 CVEsMultiple vulnerabilities have been disclosed in SonicWall Gen6 and Gen7 firewalls, SonicOS, and NSv that can be exploited for authentication bypass, remote code execution, and privilege escalation, specifically CVE-2024-40762, CVE-2024-53704, CVE-2024-53705, and CVE-2024-53706; a proof of concept exploit is available for CVE-2024-53704, which, if exploited, can lead to internal network access and further attacks, including ransomware deployment.
Threat Actors Disabling AV and EDR Solutions
2 rules 2 TTPsThreat actors are actively disabling antivirus and EDR solutions through abusing Windows Firewall rules, uninstalling agents, and exploiting vulnerable drivers (BYOVD) to establish persistence, move laterally, and deploy ransomware undetected.
Multiple Vulnerabilities in SonicWall SonicOS Allow Privilege Escalation and DoS
2 rules 3 TTPs 3 CVEsMultiple vulnerabilities in SonicWall SonicOS allow a remote attacker to escalate privileges, bypass security measures, or cause a denial-of-service condition.
Multiple Vulnerabilities in SonicWall Products Allow for DoS and Security Policy Bypass
2 rules 2 TTPs 3 CVEsMultiple vulnerabilities in SonicWall firewalls could allow an attacker to cause a remote denial of service and security policy bypass, potentially disrupting network services and compromising security controls.
SonicWall Firewall Vulnerabilities Addressed in Security Advisory AV26-405
2 rulesSonicWall released a security advisory to address vulnerabilities in Gen6, Gen7, and Gen8 firewalls and SonicOS, urging users to update affected firmware versions to mitigate potential exploits.