CVE-2024-40766 Exploited by Ransomware Groups Targeting SonicWall Firewalls
ID: a19ce6ef-6b5c-53eb-b413-a30b8bd76799
STIX ID: report--a19ce6ef-6b5c-53eb-b413-a30b8bd76799
Feed Name: ThreatCluster
Threat Score
CVE-2024-40766 is an improper access control vulnerability in SonicWall SonicOS (CVSS 9.3) that has been exploited in the wild since September 2024 by ransomware groups (Akira and Fog), leading to rapid encryptions (often under four hours) and widespread compromise; an associated MySonicWall breach exposed configuration backups and encrypted credentials, and nearly 49,000 devices remained publicly exposed and unpatched as of December 2024 with exploitation continuing into 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
