CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

A New SonicWall Scanning Spike Echoes the Pattern That Preceded CVE-2026-0400

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 1848

As cited

Copy frozen at (site build).

vulnerabilities

A New SonicWall Scanning Spike Echoes the Pattern That Preceded CVE-2026-0400

Security researchers at GreyNoise have detected a new spike in scanning activity targeting SonicWall devices that follows a similar pattern to activity preceding a prior vulnerability (CVE-2026-0400). The researchers are documenting the activity and providing guidance on indicators defenders should monitor.

Why it matters: Network defenders relying on SonicWall appliances need to investigate scanning patterns immediately, as historical precedent suggests this activity may precede active exploitation of a vulnerability.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

A New SonicWall Scanning Spike Echoes the Pattern That Preceded CVE-2026-0400

Security researchers at GreyNoise have detected a new spike in scanning activity targeting SonicWall devices that follows a similar pattern to activity preceding a prior vulnerability (CVE-2026-0400). The researchers are documenting the activity and providing guidance on indicators defenders should monitor.

Why it matters: Network defenders relying on SonicWall appliances need to investigate scanning patterns immediately, as historical precedent suggests this activity may precede active exploitation of a vulnerability.

VendorsSonicWall
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary