UK Council Attack Linked to Mass Exploitation of SonicWall Flaw
Brief
A critical SonicWall flaw was rapidly weaponized, with a UK Council attack linked to a campaign that exposed credentials and enabled Active Directory theft.
On July 17, 2026, the Borough Council of King’s Lynn and West Norfolk announced it had detected a cyberattack affecting council services. Hunt. io has since published a detailed technical analysis linking that incident, with moderate confidence, to a wider mass-exploitation campaign against SonicWall SMA1000 appliances using CVE-2026-15409 , a maximum-severity SSRF flaw that received a CVSS score of 10.
- CVE-2026-15409 affects the WorkPlace portal’s WebSocket proxy. An attacker does not need to log in. By sending a specially crafted request to /wsproxy , they can make the appliance connect to port 1050 on its own local system, where a CouchDB-related Erlang service is running.
