Critical SonicWall Firewall Vulnerability Under Active Exploitation
Key Takeaways Internet-wide scanning of SonicWall firewall management interfaces has surged dramatically, potentially signaling pre-disclosure reconnaissance for new vulnerabilities. Over 597,000...
Key Takeaways
- Internet-wide scanning of SonicWall firewall management interfaces has surged dramatically, potentially signaling pre-disclosure reconnaissance for new vulnerabilities.
- Over 597,000 scanning sessions were recorded on May 12, 2026, a 46-fold increase over the daily average, primarily targeting ports 80 and 8080.
- This activity mirrors previous spikes that preceded the public disclosure of SonicWall vulnerabilities, such as CVE-2026-0400.
- While no new CVE has been confirmed, organizations are urged to immediately restrict access, enforce MFA, and prepare for rapid patching.
Unusual Surge in SonicWall Firewall Scans Raises Alarm
Cybersecurity experts are closely monitoring a significant increase in internet-wide scanning activity targeting SonicWall firewall management interfaces. This pronounced uptick has raised concerns that threat actors may be conducting reconnaissance in anticipation of exploiting new, as-yet-undisclosed vulnerabilities.
Table Of Content
Threat intelligence provider GreyNoise observed a substantial rise in scanning directed at SonicWall SonicOS management APIs between May 9 and May 18, 2026. This period saw a notable surge in probing attempts against these critical network devices.
The peak of this scanning frenzy occurred on May 12, when GreyNoise recorded approximately 597,000 sessions in a single 24-hour period. This volume represents an astonishing 46-fold increase compared to the average daily activity observed over the preceding 30 days.
This single-day volume marks the highest recorded on the GreyNoise SonicWall SonicOS API Scanner tag in the past 90 days, strongly suggesting a coordinated and large-scale reconnaissance effort aimed at exposed firewall interfaces.
Historical Precedent: Scanning Spikes and Vulnerability Disclosures
Researchers at GreyNoise highlighted that similar scanning spikes earlier this year preceded the public disclosure of CVE-2026-0400, a SonicWall vulnerability announced on February 24, 2026. Previous spikes on January 18, January 30, and February 14 occurred 37, 25, and 10 days, respectively, before that particular disclosure.
While this correlation does not definitively confirm the existence of a new vulnerability, it illustrates a recurring pattern where malicious actors intensify their probing activities prior to public disclosures or the launch of exploitation campaigns. GreyNoise emphasized that the current spike serves as a warning signal rather than a direct prediction, potentially indicating early-stage reconnaissance.
Analysis of Attacker Infrastructure and Techniques
An in-depth analysis of the recent GreyNoise scanning traffic has revealed consistent tooling and infrastructure used by the attackers:
- Tooling: Nearly 99% of all requests utilized a Chrome 119 user-agent on Linux x86_64, a fingerprint consistent with earlier campaigns where 94.5% of traffic shared this characteristic.
- Source Infrastructure: A significant portion, around 56% of the traffic, originated from networks within the Netherlands, with another 44% coming from Ukraine. Together, these two countries accounted for over 99% of all observed sessions.
- ASN Concentration: A single autonomous system, AS211736, was responsible for approximately half of the total scanning volume.
- Targeted Services: The scanning activity almost exclusively focused on ports 80 and 8080 (HTTP), indicating a specific interest in web-based management interfaces.
- Classification: The majority of the source IP addresses involved in this scanning have been categorized as suspicious by GreyNoise.
What You Should Do
Given the scale and pattern of this activity, security teams managing SonicWall devices should take immediate, proactive measures to reduce their exposure and fortify their defenses against potential exploitation attempts.
- Restrict Access: Limit SonicOS management API and SSL VPN access exclusively to trusted IP ranges.
- Remove Public Exposure: Ensure that firewall management interfaces are not publicly exposed to the internet.
- Enforce MFA: Mandate multi-factor authentication (MFA) for all SSL VPN users.
- Audit Accounts: Conduct thorough audits of systems for any unauthorized administrative accounts created after May 1, 2026.
- Deploy Blocklists: Implement dynamic IP blocklists to filter out known suspicious sources identified in threat intelligence feeds.
- Monitor Advisories: Continuously track SonicWall PSIRT advisories for any new vulnerability disclosures.
- Prepare for Patches: Be ready to apply any new patches or updates within 24 hours of their release.
- Increase Logging: Enhance log retention periods and configure alerts for unusual outbound network activity.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.