CVE-2026-0400General(sonicwall / nsa_2700)

LOWCVSS 4.9 · MEDIUM

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch sonicwall nsa_2700 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A post-authentication Format String vulnerability in SonicOS allows a remote attacker to crash a firewall.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-134

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nsa_2700
  • nsa_2800
  • nsa_3700
  • nsa_3800

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • General: 4 classified signals
  • Disclosure: 3 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-05-22)
  • 8 total mentions across 3 days

Affected systems

Vendors
Products
nsa_2700nsa_2800nsa_3700nsa_3800nsa_4700nsa_4800nsa_5700nsa_5800nsa_6700nssp_10700

1 version affected across 33 products

Deep dive

Activity timeline8 mentions / 3d
01234Mentions · 2026-02-25: 2Mentions · 2026-05-21: 2Mentions · 2026-05-22: 4Patch / Workaround · 2026-05-22: 2Technical Details · 2026-02-25: 2Technical Details · 2026-05-22: 102-2505-2105-22
Signal classification3 categories
General
450.0%
Disclosure
337.5%
Patch
112.5%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-252
Disclosure2
2026-05-212
General2
2026-05-224
Disclosure1General2Patch1
Full discourse8 posts
  • GreyNoise@GreyNoiseIO
    General

    A scanning pattern similar to the one preceding CVE-2026-0400 in February is active again. May 12 saw the largest single-day session volume on this SonicWall tag in 90 days. 🔗https://www.greynoise.io/blog/sonicwall-scanning-spike-echoes-pattern-preceded-cve-2026-0400 #GreyNoise #ThreatIntel #SonicWall https://t.co/o6zmvUDzXm

    Post summary

    The tweet reports that scanning activity similar to that before CVE‑2026‑0400 resumed, reaching a 90‑day peak on May 12, but provides no PoC, exploitation details, or mitigation information.

    0301421.7K
    29.3K followersView on X
  • DFIR Radar@DFIR_Radar
    General

    New SonicWall scanning spike hits 597K sessions on May 12 — 46× normal volume with identical tooling from Netherlands/Ukraine infrastructure. Pattern mirrors the January-February sequence that preceded CVE-2026-0400. #DFIR_Radar https://t.co/fxkguusXI6

    Post summary

    The tweet reports a significant spike in SonicWall scanning traffic linked to CVE‑2026‑0400 but provides no additional technical, exploit, or patch information.

    10020173
    1.8K followersView on X
  • Lindsey O’Donnell Welch@LindseyOD123
    Disclosure

    Something to watch (also shoutout to @GreyNoiseIO for always having great intel 🫶) https://www.greynoise.io/blog/sonicwall-scanning-spike-echoes-pattern-preceded-cve-2026-0400

    Post summary

    The tweet references a GreyNoise blog about a SonicWall scanning spike that preceded CVE-2026-0400, indicating a vulnerability announcement, but provides no PoC, exploit, active exploitation, patch, or technical details.

    00010292
    3.6K followersView on X
  • Vistem Solutions@VistemSolutions
    Patch

    Scanning spikes are often an early warning sign. When activity targeting SonicWall devices mirrors patterns seen before a known CVE, defenders should treat it as a signal to verify exposure, harden access, and increase monitoring before exploitation escalates. What organizations should prioritize now: - Identify all SonicWall devices and confirm firmware versions and exposure - Apply available patches, hotfixes, and vendor-recommended mitigations - Restrict management interfaces with VPN/Zero Trust, IP allowlisting, and MFA - Review logs for unusual scanning, failed authentication, suspicious admin activity, and configuration changes - Disable unused services and reduce internet-facing attack surface - Monitor for lateral movement or abnormal outbound traffic from edge devices 𝗩𝗶𝘀𝘁𝗲𝗺 𝗘𝗹𝗲𝘃𝗮𝘁𝗲 𝗽𝗼𝘄𝗲𝗿𝗲𝗱 𝗯𝘆 𝗩𝗶𝘀𝘁𝗲𝗺𝗦𝗲𝗰𝘂𝗿𝗲𝗣𝗿𝗼 helps organizations validate exposure, prioritize remediation, and strengthen edge security with vCISO-led strategy, continuous monitoring, and measurable risk reduction. Contact: sales@vistem.com | http://www.vistem.com?utm_source=in_page&utm_medium=Vistem+Solutions%2C+Inc.&utm_campaign=publer #Cybersecurity #SonicWall #ThreatIntel #VulnerabilityManagement #EdgeSecurity #NetworkSecurity #IncidentResponse #ZeroTrust #CyberResilience #VistemElevate #VistemSecurePro #VistemSolutions #SecurityCompliance https://www.greynoise.io/blog/sonicwall-scanning-spike-echoes-pattern-preceded-cve-2026-0400?utm_source=in_page&utm_medium=Vistem+Solutions%2C+Inc.&utm_campaign=publer

    Post summary

    The post offers a security advisory urging organizations to confirm exposure, apply the latest patches and hotfixes for SonicWall devices, and harden management interfaces to mitigate the identified CVE‑2026‑0400 threat.

    0000039
    79 followersView on X
  • RST Cloud@rst_cloud
    General

    #threatreport #LowCompleteness A New SonicWall Scanning Spike Echoes the Pattern That Preceded CVE-2026-0400 | 22-05-2026 Source: https://www.greynoise.io/blog/sonicwall-scanning-spike-echoes-pattern-preceded-cve-2026-0400 Key details below ↓ 🎯Victims: Sonicwall users, Ssl vpn users 🌐Geo: Netherlands, Ukraine 🔓CVEs: CVE-2026-0400 \[[Vulners](https://vulners.com/cve/CVE-2026-0400)] - CVSS V3.1: *4.9*, - Vulners: Exploitation: Unknown Soft: - sonicwall sonicos (<7.3.2-7010) 🤖LLM extracted TTPs:` T1595 🧨IOCs: - IP: 5 💽Software: Slack, SonicOS, Chrome, Linux #threatreport: Recent observations by GreyNoise indicate a substantial increase in scanning activity targeting SonicWall SonicOS management interfaces between May 9 and May 18, 2026. The peak occurred on May 12, with around 597,000 sessions recorded, marking a staggering 46 times the usual daily volume for this tag. Such spikes have historically preceded the disclosure of vulnerabilities affecting SonicWall products. Notably, previous activity spikes occurred on January 18, January 30, and February 14, which all preceded the February 24 release of CVE-2026-0400. Analysis of the scanning activity shows that approximately 99% of the requests identified a singular browser user-agent—Chrome 119 on Linux x86_64—consistent with the patterns observed during the earlier spikes. This continuity suggests that the same tooling is being employed in the current wave of scanning. Regarding the origins of these sessions, about 56% come from networks in the Netherlands, and 44% from Ukraine, indicating a highly concentrated threat landscape, with a single Autonomous System Number (ASN) accounting for roughly half of all sessions. Importantly, many of the IP addresses involved have been classified as suspicious by GreyNoise. The specific services targeted during this spike are predominantly found on ports 80 and 8080 (HTTP), aligning with established tactics commonly employed in the reconnaissance phase of cyber attacks. In response to the potential threat this activity signifies, defenders are advised to take several precautionary measures. These include restricting access to the SonicOS management API and SSL VPN portal to known administrative IP ranges, which would mitigate the risk of unauthorized access. Public exposure of management interfaces should be eliminated alongside mandatory multi-factor authentication (MFA) for all SSL VPN accounts. Additionally, it is recommended to conduct audits of the SonicOS configuration to identify any new administrative accounts created since May 1, 2026, and to employ a dynamic IP blocklist at the network perimeter to further protect against potential exploitation.

    Post summary

    The post reports a significant spike in scanning targeting SonicWall SonicOS interfaces, correlating with the release of CVE‑2026‑0400, and offers mitigation guidance but lacks evidence of active exploitation or a PoC.

    0000075
    660 followersView on X
  • ohhara_P🧐Slow life in the isekai@ohhara_shiojiri
    General

    A New SonicWall Scanning Spike Echoes the Pattern That Preceded CVE-2026-0400 https://www.greynoise.io/blog/sonicwall-scanning-spike-echoes-pattern-preceded-cve-2026-0400

    Post summary

    The article notes a new SonicWall scanning spike that echoes patterns seen before CVE-2026-0400, yet it does not contain PoC, exploit details, or patch information.

    0000067
    2.0K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    CVE-2026-0399, CVE-2026-0400, CVE-2026-0401, CVE-2026-0402 SonicOS multiple post-authentication vulnerabilities https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0001

    Post summary

    SonicOS has disclosed four post-authentication vulnerabilities (CVE-2026-0399 to CVE-2026-0402) and provided a vendor advisory link for further details.

    00000377
    6.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-0400 A post-authentication Format String vulnerability in SonicOS allows a remote attacker to crash a firewall. https://www.cve.org/CVERecord?id=CVE-2026-0400

    Post summary

    The post‑authentication format string vulnerability CVE‑2026‑0400 in SonicOS can cause a firewall crash, but no PoC, exploit, patch, or active exploitation is mentioned.

    00000176
    56.6K followersView on X
CPE platform detail33 entries

33 of 33 entries

PartVendorProductVersionTarget SWTarget HW
HWsonicwallnsa_2700---
HWsonicwallnsa_2800---
HWsonicwallnsa_3700---
HWsonicwallnsa_3800---
HWsonicwallnsa_4700---
HWsonicwallnsa_4800---
HWsonicwallnsa_5700---
HWsonicwallnsa_5800---
HWsonicwallnsa_6700---
HWsonicwallnssp_10700---
HWsonicwallnssp_11700---
HWsonicwallnssp_13700---
HWsonicwallnssp_15700---
HWsonicwallnsv270---
HWsonicwallnsv470---
HWsonicwallnsv870---
OSsonicwallsonicos---
HWsonicwalltz270---
HWsonicwalltz270w---
HWsonicwalltz280---
HWsonicwalltz370---
HWsonicwalltz370w---
HWsonicwalltz380---
HWsonicwalltz470---
HWsonicwalltz470w---
HWsonicwalltz480---
HWsonicwalltz570---
HWsonicwalltz570p---
HWsonicwalltz570w---
HWsonicwalltz580---
HWsonicwalltz670---
HWsonicwalltz680---
HWsonicwalltz80---

Explore more