Vulnerabilities

SonicWall Hunts for Zero-Day Amid Surge in Firewall Exploitation

Threat actors might be exploiting a zero-day vulnerability in SonicWall firewalls in a fresh wave of ransomware attacks.

SonicWall vulnerability

A recent surge in ransomware attacks targeting SonicWall firewalls for initial access suggests that a potential zero-day vulnerability is being exploited, security researchers warn.

Google Threat Intelligence Group (GTIG) was the first to warn of the new wave of activity in mid-July, when it noted that login information stolen in previous attacks was likely used to compromise SonicWall appliances that had been fully patched against known vulnerabilities.

As part of the observed incidents, the threat actors were deploying a new backdoor/user-mode rootkit dubbed Overstep, which was designed to modify the device’s boot process for persistence and data theft.

At the same time, GTIG noted that the threat actor behind the attacks, tracked as UNC6148, “may have used an unknown zero-day remote code execution vulnerability to deploy Overstep on opportunistically targeted SonicWall SMA appliances”.

In early August, cybersecurity firms Arctic Wolf and Huntress issued fresh alerts on cyberattacks targeting SonicWall appliances to bypass MFA, and SonicWall acknowledged the surge in activity, noting it was looking into the potential exploitation of a zero-day.

“We are actively investigating these incidents to determine whether they are connected to a previously disclosed vulnerability or if a new vulnerability may be responsible,” SonicWall said on Monday.

Advertisement. Scroll to continue reading.

Arctic Wolf said it has observed attacks involving VPN access through SonicWall SSL VPNs, and that collected evidence points to a zero-day flaw.

“In some instances, fully patched SonicWall devices were affected following credential rotation. Despite TOTP MFA being enabled, accounts were still compromised in some instances,” the company said.

Huntress too warns of successful attacks against appliances with MFA enabled, noting that the threat actors were seen pivoting to domain controllers within hours after initial access.

“During our investigation into telemetry related to this activity, we’ve found evidence to suggest that this compromise may be limited to TZ and NSa-series SonicWall firewalls with SSLVPN enabled. We can confirm that the suspected vulnerability exists in firmware versions 7.2.0-7015 and earlier,” Huntress said.

The campaign is targeting Gen 7 SonicWall firewalls with SSLVPN enabled, and SonicWall recommends that customers disable SSLVPN services, limit the SSLVPN connectivity to trusted IPs, enable security services to detect threat activity, enforce MFA, remove unused accounts, and ensure that all passwords are updated.

“Please remain vigilant and apply the above mitigations immediately to reduce exposure while we continue our investigation,” SonicWall noted.

Related: SonicWall Patches Critical SMA 100 Vulnerability, Warns of Recent Malware Attack

Related: Apple Patches Safari Vulnerability Flagged as Exploited Against Chrome

Related: High-Severity Flaws Patched in Chrome, Firefox

Related: New ‘ResolverRAT’ Targeting Healthcare, Pharmaceutical Organizations

Related Content

Cybercrime

Oleksii Oleksiyovych Lytvynenko has been sentenced to 4 years in prison after he was arrested in Ireland in 2023.

Vulnerabilities

Cisco and CISA have flagged exploitation of CVE-2026-20079, a vulnerability disclosed in March 2026.

Vulnerabilities

Administrators are advised to check their deployments for newly created user accounts they don’t recognize.

Vulnerabilities

The proof-of-concept (PoC) exploits lead to privilege escalation, spawning a shell with System privileges.

Vulnerabilities

Google’s Chrome 152 security update resolves 12 vulnerabilities, including a high-severity type confusion flaw in the V8 engine.

Vulnerabilities

The vulnerabilities CVE-2026-83549 and CVE-2026-83548 can be chained for unauthenticated remote code execution.

Data Breaches

The company has notified the SEC that hackers accessed patient, employee, provider, business, and financial information.

Vulnerabilities

CISA has added the vulnerabilities tracked as CVE-2026-82078 and CVE-2026-81578 to its KEV catalog.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version