logo

SonicWall SSLVPN access control flaw is now exploited in attacks

ID: 53517b5b-562d-53b9-975b-6f5ff6da4c1c

STIX ID: report--53517b5b-562d-53b9-975b-6f5ff6da4c1c

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-09-06

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

SonicWall has issued an urgent advisory for CVE-2024-40766, a critical (CVSS 9.3) access-control flaw in SonicOS affecting Gen5/6/7 devices including SSLVPN; administrators are urged to apply vendor patches and mitigations (restrict management access, disable or limit SSLVPN, enforce MFA and password resets). The vendor reports potential exploitation in the wild and security firms have observed Akira ransomware campaigns targeting this vulnerability.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.