Affected Systems

SonicWall Gen6 SSL-VPN appliances with incomplete patching. Specific firmware versions not disclosed. Affects organizations using SonicWall SSL-VPN for remote access.

Exploitation Status

Active exploitation confirmed. Threat actors are brute-forcing VPN credentials, bypassing MFA, and deploying ransomware tooling on incompletely patched SonicWall Gen6 SSL-VPN devices.

Business Impact

Critical risk for organizations with SonicWall Gen6 SSL-VPN appliances. Successful exploitation grants attackers authenticated VPN access despite MFA, enabling lateral movement and ransomware deployment. No CVE assigned yet, suggesting potential zero-day or undisclosed vulnerability. Immediate verification of patch status and credential security required.

Urgency

🔴 Immediate

Recommended Actions

  • Verify all SonicWall Gen6 SSL-VPN appliances are fully patched to the latest firmware version available from SonicWall support portal
  • Review VPN authentication logs for brute-force attempts, unusual login patterns, or MFA bypass indicators
  • Enforce strong password policies and implement account lockout thresholds to mitigate brute-force attacks
  • Enable additional network segmentation and monitoring for VPN-connected devices to detect lateral movement
  • Contact SonicWall support to confirm patch applicability and obtain specific remediation guidance for Gen6 appliances