securityonline.info 11 Sept 2026, 04:42 UTC

SonicWall Flaw Exposed 160 Active Directory Domains to Attackers

SonicWall Flaw Exposed 160 Active Directory Domains to Attackers
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Available

A campaign exploiting CVE-2026-15409 has been observed targeting SonicWall SMA1000 appliances, with activity linked to a UK local government infrastructure among other sectors. The operation began shortly after SonicWall disclosed the flaw on 14 July 2026, with mass internet scanning for unpatched devices followed by credential theft and internal network pivoting.

The attacker used a modified public proof‑of‑concept to reach affected appliances, gaining command execution, extracting stored configurations and LDAP credentials, and retrieving policy_file.xml files that stored encrypted administrator credentials. The adversary decrypted LDAP bind passwords, enabling direct access to internal directory services and setting the stage for broader propagation.

Evidence from the investigation indicates a deliberate move into Active Directory environments via a local Linux build of Impacket’s secretsdump, deployed from within compromised SMA1000 gateways. The intruder leveraged the gateway as an internal proxy to minimise detection, performing DCSync operations to harvest passwords and Kerberos keys across multiple domains.

In total, 250 targets were identified, with 168 appliances exposing configuration data and 534 configuration records across 160 distinct Active Directory domains exposed. The breach affected organisations across France, India, Italy, the United States, Canada, Germany, Sweden and the United Kingdom, spanning local government, healthcare, financial services and higher education.

Mitigation guidance emphasises applying SonicWall firmware hotfixes for CVE-2026-15409, rotating directory bind passwords on perimeter devices, resetting domain controller computer accounts, inspecting temporary directories on appliances for rogue files, restricting management interfaces, and auditing AD replication permissions. Organizations are advised to treat unpatched gateways as potentially compromised and to perform comprehensive credential resets to eradicate lingering access.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline