Skip to content
Threat Feed

Vendor

SonicWall

23 briefs RSS
high advisory

Multiple Vulnerabilities in SonicWall Network Security Manager

SonicWall Network Security Manager (NSM) versions prior to 4.3.1-R4 contain multiple vulnerabilities, including CVE-2026-78327, CVE-2026-78328, and CVE-2026-81939, that allow for remote code execution, privilege escalation, and security policy bypass.

Network Security Manager On-Prem vulnerability remote-code-execution privilege-escalation patch-management
critical advisory

Critical SSRF Vulnerability in SonicWall SMA1000 Appliances

SonicWall SMA1000 appliances are vulnerable to an unauthenticated server-side request forgery (SSRF) flaw, enabling remote attackers to access sensitive internal functionality and perform unauthorized operations.

SMA1000 Appliances vulnerability ssrf network-appliance
1t 2c
high threat

Active Exploitation of SonicWall SMA 1000 Series Appliances

SonicWall has addressed two actively exploited vulnerabilities, CVE-2024-5091 and CVE-2024-5092, in the SMA 1000 series that allow for unauthenticated unauthorized actions and authenticated command execution.

exploited SMA 1000 Series
2t 2c
medium advisory

Security Policy Bypass Vulnerabilities in SonicWall NetExtender

Multiple vulnerabilities, CVE-2026-66152 and CVE-2026-66153, in SonicWall NetExtender Linux Client versions prior to 10.3.6 allow attackers to bypass security policy enforcement.

NetExtender Linux Client
2c
medium advisory

Detection of Anomalous SonicWall Remote Access Logins

This detection logic identifies potentially unauthorized remote or administrative VPN access by monitoring for successful login combinations of user, source IP, and appliance not observed in the previous 14 days.

SonicWall Firewall identity-and-access-audit initial-access network-security
1r 2t
high threat

Akira Ransomware Affiliate Abuses Safe Mode to Evade EDR

An Akira ransomware affiliate gained initial access via a SonicWall VPN and attempted to evade security controls by rebooting the host into Safe Mode, an anti-EDR tactic that ultimately caused the ransomware to crash.

SonicWall SSL VPN +1 Akira ransomware edr-evasion sonicwall
1r 2t 3i
high advisory

Multiple Vulnerabilities in SonicWall Global Management System

Multiple vulnerabilities in SonicWall Global Management System (GMS) present risks for remote code execution by unauthenticated attackers.

Global Management System
2t
high advisory

Multiple Vulnerabilities in SonicWall GMS

SonicWall GMS contains multiple vulnerabilities allowing remote code execution with root privileges, privilege escalation, security bypass, and information disclosure.

GMS vulnerability network-security sonicwall
3t
medium advisory

Multiple Vulnerabilities in SonicWall Email Security

SonicWall Email Security contains multiple local vulnerabilities that permit an attacker to execute arbitrary code with administrative privileges, leading to full appliance compromise.

Email Security
1t
critical threat

Active Exploitation of SonicWall SMA 1000 Series Appliances by Ransomware Actors

CISA has added CVE-2024-40766 to its Known Exploited Vulnerabilities catalog after reports that ransomware actors are leveraging the flaw in SonicWall SMA 1000 series appliances to gain initial access to enterprise networks.

exploited SMA 1000 ransomware vulnerability cve-2024-40766
1t 1c
medium advisory

Denial of Service Vulnerability in SonicWall Global VPN Client

A vulnerability (CVE-2026-66151) in SonicWall Global VPN Client versions prior to 5.0.0.2008 allows remote attackers to trigger a denial of service condition.

Global VPN Client
1t 1c
high advisory

Security Policy Bypass in SonicWall SonicOS

A security policy bypass vulnerability (CVE-2026-0516) in SonicWall SonicOS affects multiple hardware generations and virtual appliances, potentially allowing unauthorized access or configuration subversion.

SonicOS +3 vulnerability network-security firewall
1c
critical threat

CVE-2026-63030: Critical Remote Code Execution Vulnerability in WordPress Core

CVE-2026-63030 is a critical unauthenticated remote code execution vulnerability affecting WordPress Core versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1, allowing an unauthenticated attacker to execute arbitrary code via the WordPress REST API batch endpoint, potentially leading to complete website compromise.

exploited PoC WordPress Core 6.9.0 +51 wordpress rce web-vulnerability cve
2t 15c 8i updated
critical advisory

SonicWall SMA: Multiple Vulnerabilities

Multiple vulnerabilities in SonicWall SMA allow an unauthenticated, remote attacker to bypass security mechanisms and execute arbitrary operating system commands on the affected system, leading to full compromise of the appliance.

SonicWall SMA vulnerability rce sonicwall network-appliance
3t
high threat

SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability (CVE-2026-15409)

A critical server-side request forgery (SSRF) vulnerability, identified as CVE-2026-15409, exists in SonicWall SMA1000 Appliances, allowing a remote, unauthenticated attacker to force the appliance to make requests to arbitrary internal or external locations, potentially leading to information disclosure or access to restricted network services.

exploited PoC SMA1000 Appliances +6 ssrf vulnerability cisa-kev remote-code-execution network-appliance
2t 2c 6i updated
high advisory

Plain Text Passwords: A Direct Path to Organizational Compromise

A threat actor, after gaining initial access via a SonicWall VPN vulnerability, exploited plain text Huntress portal recovery codes found on a security engineer's desktop to infiltrate the security platform, enabling defense evasion and furthering malicious activity.

SonicWall VPNs +1 credential-theft defense-evasion ransomware plain-text-passwords initial-access security-platform-compromise
2r 4t 2i
high threat

SonicWall Gen6 SSL-VPN MFA Bypass via CVE-2024-12802

Threat actors exploited CVE-2024-12802, a vulnerability in SonicWall Gen6 SSL-VPN appliances, to bypass multi-factor authentication (MFA) after brute-forcing VPN credentials, leading to the deployment of ransomware-related tools.

Gen6 SSL-VPN appliances +2 Initial Access Broker vpn mfa-bypass cve-2024-12802 sonicwall initial access
2r 1t 1c
high threat

Ransomware-as-a-Service (RaaS) Ecosystem: Affiliate Tradecraft and Initial Access Vectors

Ransomware-as-a-service (RaaS) attacks leverage affiliates for initial access, persistence, and exfiltration, using varied techniques like compromised RDP, vulnerable VPNs, and rogue RMM tools, impacting multiple organizations in a single campaign.

Remote Desktop Protocol +7 ransomware raas initial-access persistence
2r 1t
critical advisory

Multiple Vulnerabilities in SonicWall Firewalls Allow Remote Code Execution and Privilege Escalation

Multiple vulnerabilities have been disclosed in SonicWall Gen6 and Gen7 firewalls, SonicOS, and NSv that can be exploited for authentication bypass, remote code execution, and privilege escalation, specifically CVE-2024-40762, CVE-2024-53704, CVE-2024-53705, and CVE-2024-53706; a proof of concept exploit is available for CVE-2024-53704, which, if exploited, can lead to internal network access and further attacks, including ransomware deployment.

Gen6 Hardware Firewalls +5 sonicwall firewall rce authentication-bypass privilege-escalation
1r 3t 4c
high advisory

Threat Actors Disabling AV and EDR Solutions

Threat actors are actively disabling antivirus and EDR solutions through abusing Windows Firewall rules, uninstalling agents, and exploiting vulnerable drivers (BYOVD) to establish persistence, move laterally, and deploy ransomware undetected.

Defender Antivirus +2 defense-evasion privilege-escalation byovd
2r 2t
high threat

Multiple Vulnerabilities in SonicWall SonicOS Allow Privilege Escalation and DoS

Multiple vulnerabilities in SonicWall SonicOS allow a remote attacker to escalate privileges, bypass security measures, or cause a denial-of-service condition.

exploited SonicOS sonicwall vulnerability privilege-escalation denial-of-service
2r 3t 3c
medium advisory

Multiple Vulnerabilities in SonicWall Products Allow for DoS and Security Policy Bypass

Multiple vulnerabilities in SonicWall firewalls could allow an attacker to cause a remote denial of service and security policy bypass, potentially disrupting network services and compromising security controls.

SOHOW +65 sonicwall firewall dos security_bypass
2r 2t 3c
high advisory

SonicWall Firewall Vulnerabilities Addressed in Security Advisory AV26-405

SonicWall released a security advisory to address vulnerabilities in Gen6, Gen7, and Gen8 firewalls and SonicOS, urging users to update affected firmware versions to mitigate potential exploits.

Gen6 Hardware Firewalls +4 firewall vulnerability sonicwall
2r