people · May 21, 2026
Hackers Exploit SonicWall VPN Flaw After Incomplete Patching According to ReliaQuest Report
Share the canonical public link.
Cybersecurity Dive reported on 19 May 2026 that ReliaQuest identified threat actors brute-forcing SonicWall Gen6 SSL-VPN credentials and bypassing MFA silently since February 2026. The attacks followed a consistent pattern of automated credential testing, internal reconnaissance, and voluntary logout within 30 to 60 minutes per incident. ReliaQuest researchers stated that as few as 13 brute-force attempts succeeded in one case and that the activity aligned with ransomware ecosystem initial access brokers. The report highlighted that firmware patching alone leaves the vulnerable LDAP configuration intact on Gen6 appliances. CISA rates CVE-2024-12802 at 9.1 CVSS while SonicWall assigned 6.5.