HomeIntelligenceBrief
BREACH BRIEF 🔴 Critical Breach

Mass Exploitation of SonicWall SMA1000 SSRF Flaw (CVE‑2026‑15409) Leads to Credential Theft at UK Council

A critical SSRF vulnerability in SonicWall SMA1000 appliances (CVE‑2026‑15409) was weaponized in a mass‑exploitation campaign that stole Active Directory credentials from the Borough Council of King’s Lynn and West Norfolk. The incident underscores the need for continuous monitoring of network‑device configurations and robust credential‑access controls for audit readiness.

Verisq™ Intelligence · 📅 September 11, 2026 · 📰 securityaffairs.com
🔴
Severity
Critical
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
securityaffairs.com

Mass Exploitation of SonicWall SMA1000 SSRF Flaw (CVE‑2026‑15409) Leads to Credential Theft at UK Council

What Happened — A critical SSRF vulnerability (CVE‑2026‑15409, CVSS 10.0) in SonicWall SMA1000 appliances was weaponized in a mass‑exploitation campaign. The flaw allowed unauthenticated attackers to reach an internal Erlang service, use a hard‑coded cookie, and execute OS commands, ultimately dumping Active Directory credentials from the victim’s network. The Borough Council of King’s Lynn and West Norfolk confirmed that the attack leveraged this chain to steal hundreds of AD accounts.

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for continuous monitoring of firewall/VPN appliance configurations and evidence that patches are applied promptly.
  • Highlights gaps in credential protection and privileged‑account visibility that a control‑assurance program must capture and audit.
  • Shows how a single unpatched network device can become a foothold for large‑scale credential theft, underscoring the importance of robust access‑control controls and defensible logs.

Who Is Affected – Local government bodies, public‑sector IT departments, and any organization relying on SonicWall SMA appliances for remote access.

Recommended Actions

  • Verify firmware version on all SonicWall SMA devices; apply SonicWall’s July 14 advisory patch immediately.
  • Deploy continuous configuration monitoring to detect unauthorized changes to firewall management interfaces.
  • Enforce strict credential‑access monitoring and rotate privileged AD passwords after any suspected compromise.
  • Incorporate firewall logs into your SIEM/EDR to surface anomalous internal connections.

Technical Notes – The SSRF exploits the WorkPlace portal’s WebSocket proxy (/wsproxy) to reach a local CouchDB Erlang node on port 1050. A hard‑coded cookie authenticates the attacker, who then runs commands as the couchdb user. The exploit chain can be automated in seconds and was observed in the wild within three days of the vulnerability’s disclosure. Source: SecurityAffairs

📰 Original Source
https://securityaffairs.com/198864/hacking/uk-council-attack-linked-to-mass-exploitation-of-sonicwall-flaw.html

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →