Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Levi Strauss Data Breach Exposes Customer and Employee Data
August 8, 2026
OpenAI Pauses Astra Model Development to Assess Cybersecurity Risks
August 8, 2026
Critical Linux Kernel SCTP Vulnerability Lets Attackers Gain Root
August 7, 2026
Home/CyberSecurity News/Critical SonicWall Firewall Vulnerability Under Active Exploitation
CyberSecurity News

Critical SonicWall Firewall Vulnerability Under Active Exploitation

Key Takeaways Internet-wide scanning of SonicWall firewall management interfaces has surged dramatically, potentially signaling pre-disclosure reconnaissance for new vulnerabilities. Over 597,000...

Sarah simpson
Sarah simpson
May 25, 2026 3 Min Read
62 0

Key Takeaways

  • Internet-wide scanning of SonicWall firewall management interfaces has surged dramatically, potentially signaling pre-disclosure reconnaissance for new vulnerabilities.
  • Over 597,000 scanning sessions were recorded on May 12, 2026, a 46-fold increase over the daily average, primarily targeting ports 80 and 8080.
  • This activity mirrors previous spikes that preceded the public disclosure of SonicWall vulnerabilities, such as CVE-2026-0400.
  • While no new CVE has been confirmed, organizations are urged to immediately restrict access, enforce MFA, and prepare for rapid patching.

Unusual Surge in SonicWall Firewall Scans Raises Alarm

Cybersecurity experts are closely monitoring a significant increase in internet-wide scanning activity targeting SonicWall firewall management interfaces. This pronounced uptick has raised concerns that threat actors may be conducting reconnaissance in anticipation of exploiting new, as-yet-undisclosed vulnerabilities.

Table Of Content

  • Key Takeaways
  • Unusual Surge in SonicWall Firewall Scans Raises Alarm
  • Historical Precedent: Scanning Spikes and Vulnerability Disclosures
  • Analysis of Attacker Infrastructure and Techniques
  • What You Should Do

Threat intelligence provider GreyNoise observed a substantial rise in scanning directed at SonicWall SonicOS management APIs between May 9 and May 18, 2026. This period saw a notable surge in probing attempts against these critical network devices.

The peak of this scanning frenzy occurred on May 12, when GreyNoise recorded approximately 597,000 sessions in a single 24-hour period. This volume represents an astonishing 46-fold increase compared to the average daily activity observed over the preceding 30 days.

This single-day volume marks the highest recorded on the GreyNoise SonicWall SonicOS API Scanner tag in the past 90 days, strongly suggesting a coordinated and large-scale reconnaissance effort aimed at exposed firewall interfaces.

Historical Precedent: Scanning Spikes and Vulnerability Disclosures

Researchers at GreyNoise highlighted that similar scanning spikes earlier this year preceded the public disclosure of CVE-2026-0400, a SonicWall vulnerability announced on February 24, 2026. Previous spikes on January 18, January 30, and February 14 occurred 37, 25, and 10 days, respectively, before that particular disclosure.

While this correlation does not definitively confirm the existence of a new vulnerability, it illustrates a recurring pattern where malicious actors intensify their probing activities prior to public disclosures or the launch of exploitation campaigns. GreyNoise emphasized that the current spike serves as a warning signal rather than a direct prediction, potentially indicating early-stage reconnaissance.

Analysis of Attacker Infrastructure and Techniques

An in-depth analysis of the recent GreyNoise scanning traffic has revealed consistent tooling and infrastructure used by the attackers:

  • Tooling: Nearly 99% of all requests utilized a Chrome 119 user-agent on Linux x86_64, a fingerprint consistent with earlier campaigns where 94.5% of traffic shared this characteristic.
  • Source Infrastructure: A significant portion, around 56% of the traffic, originated from networks within the Netherlands, with another 44% coming from Ukraine. Together, these two countries accounted for over 99% of all observed sessions.
  • ASN Concentration: A single autonomous system, AS211736, was responsible for approximately half of the total scanning volume.
  • Targeted Services: The scanning activity almost exclusively focused on ports 80 and 8080 (HTTP), indicating a specific interest in web-based management interfaces.
  • Classification: The majority of the source IP addresses involved in this scanning have been categorized as suspicious by GreyNoise.

What You Should Do

Given the scale and pattern of this activity, security teams managing SonicWall devices should take immediate, proactive measures to reduce their exposure and fortify their defenses against potential exploitation attempts.

  • Restrict Access: Limit SonicOS management API and SSL VPN access exclusively to trusted IP ranges.
  • Remove Public Exposure: Ensure that firewall management interfaces are not publicly exposed to the internet.
  • Enforce MFA: Mandate multi-factor authentication (MFA) for all SSL VPN users.
  • Audit Accounts: Conduct thorough audits of systems for any unauthorized administrative accounts created after May 1, 2026.
  • Deploy Blocklists: Implement dynamic IP blocklists to filter out known suspicious sources identified in threat intelligence feeds.
  • Monitor Advisories: Continuously track SonicWall PSIRT advisories for any new vulnerability disclosures.
  • Prepare for Patches: Be ready to apply any new patches or updates within 24 hours of their release.
  • Increase Logging: Enhance log retention periods and configure alerts for unusual outbound network activity.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

CVEExploitHackerPatchSecurityThreatVulnerability

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

MiniUpdate RAT Leverages Azure for Targeted Espionage Campaigns

Next Post

Italian Police Dismantle Piracy App CINEMAGOAL

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Zapscape KVM Vulnerability CVE-2026-64561 Allows Guest-to-Host Escape
August 7, 2026
Chrome 101 Patches 41 Vulnerabilities, 6 Critical Memory Bugs
August 7, 2026
Patchwork APT Uses Fake PDFs, Chat Apps to Spy on PCs, Android
August 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us