A UK local government incident has been linked to the mass exploitation of a SonicWall SMA1000 VPN/SSL appliance vulnerability, CVE-2026-15409. The Borough Council of King’s Lynn and West Norfolk said it detected a cyberattack on 17 July 2026. Hunt[.]io produced a technical analysis with moderate confidence tying the council event to a broader campaign that exploited the SSRF flaw in SonicWall’s WorkPlace WebSocket proxy.
The flaw allowed unauthenticated access to a local CouchDB/Erlang service, enabling command execution and access to credentials, with Rapid7 noting a proof-of-concept was followed by a 50-thread mass scanner within days of SonicWall’s advisory on 14 July 2026.
Evidence from the investigation shows the campaign compromised 250 appliances, exposing LDAP configuration files with credentials for hundreds of Active Directory accounts, and in several environments, attackers obtained SAM and LSA secrets or performed full DCSync replication to steal AD data across multiple domain controllers.
The attackers used a fixed 32‑byte AES key embedded in the appliance to decrypt LDAP passwords, then deployed a Linux build of Impacket’s secretsdump to extract credentials from internal Windows systems. SonicWall states fixed firmware versions start at 12.4.3-03453, but a full remediation requires re-imaging affected devices, rotating all credentials, and resetting TOTP tokens.
The report highlights how internal networks were reached via compromised appliances, which blended malicious activity with normal traffic and evaded typical endpoint detection. The affected organisations spanned local government, healthcare, finance, higher education, manufacturing and IT providers across multiple countries, including the United Kingdom.