logo

Attackers are bypassing MFA on SonicWall VPNs because something was wrong with previous fix

ID: 31ce082a-c464-5de9-a3ff-285c3ce74436

STIX ID: report--31ce082a-c464-5de9-a3ff-285c3ce74436

Feed Name: Security Affairs

Threat Score
78/100

Date Published: 2026-05-21

Date Updated: 2026-05-22

Author: Pierluigi Paganini

...
...

ReliaQuest observed active exploitation of SonicWall CVE-2024-12802 on Gen6 SSL-VPN appliances where firmware updates alone are insufficient: six manual LDAP reconfiguration steps are required to prevent an MFA bypass that lets attackers authenticate via UPN while MFA is enforced on SAM. Attackers brute-forced VPN accounts, bypassed MFA, moved quickly to file servers (sometimes within 30 minutes), attempted Cobalt Strike deployment and driver-based EDR disabling, and left log signals such as sess="CLI" and Event IDs 238/1080; Gen6 devices are end-of-life so migration to supported hardware is recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.