Skip to main content

System status

Coverage is stale.

Collection is paused. Latest public event: Aug 21, 2026 (10 days ago).

← Intel index

This coverage is stale.

Last updated May 21, 2026 (about 3 months ago).

people · May 21, 2026

Hackers Exploit SonicWall VPN Flaw After Incomplete Patching According to ReliaQuest Report

Share the canonical public link.

Share as image

Cybersecurity Dive reported on 19 May 2026 that ReliaQuest identified threat actors brute-forcing SonicWall Gen6 SSL-VPN credentials and bypassing MFA silently since February 2026. The attacks followed a consistent pattern of automated credential testing, internal reconnaissance, and voluntary logout within 30 to 60 minutes per incident. ReliaQuest researchers stated that as few as 13 brute-force attempts succeeded in one case and that the activity aligned with ransomware ecosystem initial access brokers. The report highlighted that firmware patching alone leaves the vulnerable LDAP configuration intact on Gen6 appliances. CISA rates CVE-2024-12802 at 9.1 CVSS while SonicWall assigned 6.5.

Below validation threshold — auto-passed without scoring

Supporting evidence