An unidentified threat actor mass-exploited CVE-2026-15409, a critical unauthenticated SSRF flaw in SonicWall SMA1000 WorkPlace, to reach a locally bound Erlang distribution service through the /wsproxy WebSocket endpoint. Using a hardcoded Erlang cookie, the actor reportedly obtained command execution as couchdb, adapted a public Rapid7 proof of concept for automated exploitation, and decrypted LDAP bind credentials stored in policy_file.xml.
Compromised appliances were used as pivots into internal Active Directory environments. The operator deployed a Linux build of Impacket secretsdump to extract Windows SAM and LSA secrets and attempted DCSync using privileged LDAP accounts or recovered domain-controller machine-account hashes. Hunt.io identified 250 exploitable systems, LDAP configurations on 168 targets, credential extraction affecting at least nine AD domains, and full DCSync compromises of five domains across seven domain controllers; affected sectors included government, healthcare, education, finance, manufacturing, and professional services worldwide.

See which actors are running it and whether you're in range.
9 events from the most recent confirmed update back to the earliest known activity.
The Borough Council of King’s Lynn and West Norfolk announced that it detected a cyberattack affecting council services. Hunt.io linked the incident with moderate confidence to the mass exploitation campaign targeting SonicWall SMA1000 appliances vulnerable to CVE-2026-15409.
An unidentified operator allegedly began opportunistic mass exploitation within two days of CVE-2026-15409's disclosure, using a modified public PoC against internet-facing SMA1000 appliances. The campaign was reported as global and affected organizations across multiple sectors.
At 07:40, the operator scanned a 2,197-entry target list using 50 concurrent threads, recording 163 successful checks corresponding to 112 unique endpoints. The detection-only scanner appeared modified for bulk use and contained Chinese comments.
Rapid7 published a Python proof of concept for CVE-2026-15409. The later operator tooling was assessed as a refactoring of this PoC and retained Rapid7 and Ryan Emmons credits.
SonicWall disclosed CVE-2026-15409, a CVSS 10 unauthenticated SSRF flaw in the SMA1000 WorkPlace interface, and reported that the vulnerability was being actively exploited.
The operator reportedly recovered SAM and LSA secrets from at least nine Active Directory domains and used recovered domain-controller machine-account NTLM hashes for pass-the-hash DCSync. Full DCSync was confirmed against seven domain controllers in five Active Directory environments.
The actor deployed a standalone Linux build of Impacket secretsdump to /tmp/secretsdump on selected SonicWall appliances, with payloads downloaded from 95.181.173[.]36. Decrypted LDAP credentials were then used to access configured internal LDAP servers and dump remote credentials.
The operator retrieved policy_file.xml files from compromised appliances, obtaining LDAP configurations and encrypted passwords. A script decrypted the passwords using a static 32-byte AES key recovered from ASAPPasswordUtil.class, yielding 534 LDAP configuration records across 160 AD domains.
The reported exploit used the public /wsproxy WebSocket endpoint to reach the locally bound couchdb@127.0.0.1 Erlang node on port 1050. It used a hard-coded Erlang cookie and RPC calls to execute commands through Erlang os:cmd() as the couchdb user.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcereddit.com
Open sourcehunt.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.