Attackers have been exploiting SonicWall Gen6 SSL-VPN appliances through CVE-2024-12802, a flaw that can let users with valid credentials bypass MFA when devices rely on LDAP with different handling for Active Directory UPN and SAM login formats. ReliaQuest reported intrusions between February and March 2026 in which attackers brute-forced VPN accounts, gained access in as few as 13 attempts, and moved laterally within 30 minutes, with activity linked to ransomware tradecraft including attempted Cobalt Strike deployment and efforts to disable endpoint protection. SonicWall said some Gen6 systems remain exposed even after firmware updates unless administrators also complete six manual LDAP reconfiguration steps in advisory SNWLID-2025-0001; Belgium's CCB separately warned organizations to patch multiple SonicWall vulnerabilities immediately.
At the same time, Sparx Systems Pro Cloud Server and Enterprise Architect were flagged for multiple severe vulnerabilities, including broken access control, authentication bypass, client-side authentication weakness, a race-condition-based remote code execution issue, and a denial-of-service bug tied to malformed SQL input. CERT Polska said the flaws affect Pro Cloud Server 6.1 build 167 and earlier and Enterprise Architect 17.1 and earlier, enabling arbitrary SQL execution, repository-wide compromise, malicious PHP file creation and execution, and service disruption; Belgium's CCB warned that some of the Sparx flaws are being actively exploited and urged immediate patching.

See which actors are running it and whether you're in range.
9 events from the most recent confirmed update back to the earliest known activity.
Security Affairs reported that attackers were bypassing MFA on SonicWall VPNs because the earlier fix was incomplete on some Gen6 devices unless administrators also performed manual LDAP changes. The report also noted Gen7 and Gen8 versions 7.2.0-7015 and 8.0.1-8017 incorporated the remediation steps.
Belgium's Centre for Cybersecurity issued an advisory warning that a critical and multiple high-severity vulnerabilities in Sparx Pro Cloud Server and Enterprise Architect were being actively exploited. The agency urged immediate patching.
CERT Polska said the five Sparx Systems vulnerabilities were disclosed on 19 May 2026 following coordination. The affected products were Pro Cloud Server 6.1 build 167 and below and Enterprise Architect 17.1 and below, with other versions untested.
In its disclosure, CERT Polska said Sparx Systems had been notified early in the process but did not provide details on the vulnerabilities or affected version ranges. The statement highlighted incomplete vendor communication around the issues.
CERT Polska disclosed five vulnerabilities affecting Sparx Systems Pro Cloud Server and Enterprise Architect after a coordinated disclosure process. The flaws included broken access control, authentication bypass, client-side authentication weakness, race-condition-based remote code execution, and denial of service.
SonicWall Gen6 devices reached end-of-life, increasing risk for organizations still relying on them while the MFA bypass issue persisted on incompletely remediated systems. Later reporting highlighted these appliances as especially risky after support ended.
Between February and March 2026, ReliaQuest observed attackers exploiting CVE-2024-12802 on SonicWall Gen6 SSL-VPN appliances to bypass MFA using valid credentials. The activity was linked to ransomware-style intrusions, including rapid lateral movement and attempted security-tool evasion.
SonicWall documented that fixing the Gen6 SSL-VPN MFA bypass issue required not only firmware updates but also six manual LDAP reconfiguration steps. Later reporting showed incomplete application of these steps left some devices exposed.
Belgium's Centre for Cybersecurity issued an advisory warning about multiple vulnerabilities affecting SonicWall products and urged organizations to patch immediately. The advisory indicates the issues were significant enough to merit public defensive action.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourceccb.belgium.be
Open sourcecert.pl
Open sourceccb.belgium.be
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.