Skip to main content

System status

Coverage is stale.

Collection is paused. Latest public event: Aug 21, 2026 (10 days ago).

← Intel index

This coverage is stale.

Last updated May 21, 2026 (about 3 months ago).

people · May 21, 2026

ReliaQuest Researchers Report Active Exploitation of SonicWall CVE-2024-12802 Despite Patching

Share the canonical public link.

Share as image

ReliaQuest researchers Alexander Capraro and Tristan Luikey published a report on 19 May 2026 detailing the first known in-the-wild exploitation of CVE-2024-12802. Attackers used automated brute-force tools to bypass MFA on Gen6 SonicWall SSL VPN devices via an unprotected UPN login format between February and March 2026 across multiple environments. In one case, the threat actor reached a file server and attempted Cobalt Strike beacon deployment plus BYOVD attack within 40 minutes of initial VPN access. ReliaQuest observed sess="CLI" session type in logs as the key early indicator of scripted authentication and recommended six manual LDAP reconfiguration steps beyond firmware updates for full Gen6 remediation. SonicWall Gen6 devices reached end-of-life on 16 April 2026.

Below validation threshold — auto-passed without scoring

Supporting evidence