GreyNoise[verified]@GreyNoiseIOGeneral
The tweet reports that scanning activity similar to that before CVE‑2026‑0400 resumed, reaching a 90‑day peak on May 12, but provides no PoC, exploitation details, or mitigation information.
DFIR Radar[verified]@DFIR_RadarGeneral
The tweet reports a significant spike in SonicWall scanning traffic linked to CVE‑2026‑0400 but provides no additional technical, exploit, or patch information.
Vistem Solutions[verified]@VistemSolutionsPatch
The post offers a security advisory urging organizations to confirm exposure, apply the latest patches and hotfixes for SonicWall devices, and harden management interfaces to mitigate the identified CVE‑2026‑0400 threat.
RST Cloud[verified]@rst_cloudGeneral
The post reports a significant spike in scanning targeting SonicWall SonicOS interfaces, correlating with the release of CVE‑2026‑0400, and offers mitigation guidance but lacks evidence of active exploitation or a PoC.
ohhara_P🧐Slow life in the isekai[verified]@ohhara_shiojiriGeneral
The article notes a new SonicWall scanning spike that echoes patterns seen before CVE-2026-0400, yet it does not contain PoC, exploit details, or patch information.
Lindsey O’Donnell Welch@LindseyOD123Disclosure
The tweet references a GreyNoise blog about a SonicWall scanning spike that preceded CVE-2026-0400, indicating a vulnerability announcement, but provides no PoC, exploit, active exploitation, patch, or technical details.
Autumn Good@autumn_good_35Disclosure
SonicOS has disclosed four post-authentication vulnerabilities (CVE-2026-0399 to CVE-2026-0402) and provided a vendor advisory link for further details.
CVE@CVEnewDisclosure
The post‑authentication format string vulnerability CVE‑2026‑0400 in SonicOS can cause a firewall crash, but no PoC, exploit, patch, or active exploitation is mentioned.