logo

Critical SonicWall SSLVPN bug exploited in ransomware attacks

ID: 8b81adcc-b5b9-5133-b9c1-99c80e0aecad

STIX ID: report--8b81adcc-b5b9-5133-b9c1-99c80e0aecad

Feed Name: Bleeping Computer

Threat Score
82/100

Date Published: 2024-09-09

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

SonicWall patched CVE-2024-40766—an improper access control flaw in SonicOS affecting Gen5–7 devices—after reports that ransomware affiliates (notably Akira) exploited SSLVPN accounts to gain initial access; Arctic Wolf and Rapid7 observed related activity, and CISA added the vulnerability to its Known Exploited Vulnerabilities catalog with a federal remediation deadline, while SonicWall advised firmware updates, restricting management/SSLVPN access, and enabling MFA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.