Vulnerabilities & Exploits · Web App Attack

SonicOS Scan Spike May Foreshadow Next Advisory

SonicWall SonicOS management-interface scans are not background noise here. GreyNoise says the May 9–18 surge looks like the same pre-disclosure pattern that showed up before CVE-2026-0400, so scan telemetry may be the earliest warning that a vendor issue is coming.

GreyNoise records a May 12 peak of about 597,000 sessions, the largest daily total on the SonicOS API Scanner tag in 90 days and about 46 times normal recent volume. It also maps this surge against earlier January 18, January 30, and February 14 spikes that came 37, 25, and 10 days before the February 24 disclosure of CVE-2026-0400.

The signal is still observational, not proof of a new flaw. But for SonicOS operators, repeated management-interface spikes now look like a recurring pre-disclosure indicator, not random internet noise.

1 source · May 21

CVE-2026-0400

NVD KEV

CVSS 4.9 MEDIUM: a post-authentication Format String vulnerability in SonicOS allows a remote attacker to crash a firewall. EPSS 0.4% (34th percentile).

Timeline

Sources

Vendor digest: SonicWall

Part of the PlainSec briefing for 2026-05-21

Every edition of this story: SonicOS Scan Spike May Foreshadow Next Advisory

More from today