Hackers Actively Scan SonicWall Firewalls, 597K Sessions Seen

A massive and sustained surge in reconnaissance activity targeting SonicWall SonicOS management interfaces. Between May 9 and May 18, 2026, GreyNoise recorded a dramatic spike on its SonicWall SonicOS API Scanner tag.

The May 12 peak of approximately 597,000 sessions represents the largest single-day total recorded on this tag in the past 90 days. It is roughly 46 times the typical daily baseline observed in the prior 30-day window.

GreyNoise previously documented a separate coordinated campaign in late February 2026, in which 84,142 sessions targeted SonicWall SonicOS infrastructure over just four days, with 92% of those sessions probing a single API endpoint to determine whether SSL VPN was enabled.

Actively Scan SonicWall Firewalls

This new activity draws immediate comparisons to a documented pre-disclosure sequence from Q1 2026.

Three earlier scanning spikes on January 18, January 30, and February 14, with lead times of 37, 25, and 10 days, respectively, preceded the February 24, 2026, disclosure of CVE-2026-0400.

That vulnerability is a post-authentication Format String flaw (CWE-134) in SonicOS, allowing a remote attacker with valid credentials to crash affected firewall appliances through improperly handled format string specifiers.

SonicWall Scans Surge Before Exploit (Source: greynoise)
SonicWall Scans Surge Before Exploit (Source: greynoise)

CVE-2026-0400 was patched across Gen 7 and Gen 8 firmware tracks. SonicWall has seen a steady drumbeat of serious vulnerabilities in recent months.

In April 2026, the company published advisory SNWLID-2026-0004, bundling three newly disclosed SonicOS flaws, including CVE-2026-0204, a HIGH-severity (CVSS 8.0) unauthenticated management-interface access control bypass affecting all Gen 6, Gen 7, and Gen 8 firewall platforms.

Mandatory firmware updates were issued across those platforms. The May scanning campaign carries consistent and distinctive technical fingerprints:

IndicatorDetail
User-AgentChrome 119 on Linux x86_64 (~99% of requests)
Source NetworksNetherlands (~56%), Ukraine (~44%), together >99% of volume
ASN ConcentrationSingle ASN (AS211736) carries ~50% of total sessions
Targeted PortsPort 80 and 8080 (HTTP) virtually all traffic
IP ClassificationOverwhelmingly flagged as Suspicious by GreyNoise

The Chrome 119 on Linux fingerprint is identical to the tooling that accounted for 94.5% of Q1 2026 SonicWall scanning traffic, per GreyNoise’s Ten Days Before Zero report, suggesting the same threat actor infrastructure is in operation.

SonicWall appliances have been a persistent target for ransomware operators. In mid-2025, researchers linked a wave of ransomware deployments, including Akira ransomware, to active exploitation of SonicWall SSL VPN vulnerabilities.

The 2026 SonicWall Cyber Protect Report further confirmed that threat actors are becoming faster and more precise in targeting SMBs that rely on SonicWall perimeter defenses.

Mitigation

GreyNoise is not confirming a forthcoming CVE, but given the documented lead-time window, defenders should act now:

Immediate steps:

  • Restrict SonicOS management API and SSL VPN portal to known administrative IP ranges; eliminate all public exposure
  • Enforce MFA on every SSL VPN account without exception
  • Audit all SonicOS administrative accounts created since May 1, 2026, for unauthorized entries
  • Deploy a dynamic IP blocklist at the network edge against flagged IPs from AS211736
  • Review firewall logs for requests to /api/sonicos/is-sslvpn-enabled and /sonicui/7/login/

Over the coming weeks:

  • Monitor the SonicWall PSIRT advisory feed closely and plan to apply patches within 24 hours of any new disclosure
  • Increase logging retention and configure SIEM alerts on outbound traffic anomalies from SonicWall appliances
  • Upgrade to the latest SonicOS firmware builds per platform (e.g., Gen 6: 6.5.5.2-28n or later; Gen 7: 7.3.2-7010; Gen 8: 8.2.0-8009)

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories