logo

Akira Ransomware Actors Exploit SonicWall Bug for RCE

ID: d7c8db40-d7a6-557e-9b8f-63d79417ff77

STIX ID: report--d7c8db40-d7a6-557e-9b8f-63d79417ff77

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-09-09

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

CISA added CVE-2024-40766 — a critical (CVSS 9.3) improper-access-control RCE in SonicWall SonicOS affecting Gen 5/6 and some Gen 7 devices — to its Known Exploited Vulnerabilities list after Akira ransomware affiliates were observed exploiting the flaw to compromise local SSLVPN accounts, gain full control of devices, and in some cases crash firewalls; SonicWall has issued patches and mitigation guidance and CISA has urged federal agencies to remediate promptly.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.