logo

CVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration., (Tue, Jun 23rd)

ID: 10323b09-ada5-5507-85b2-ad043682b686

STIX ID: report--10323b09-ada5-5507-85b2-ad043682b686

Feed Name: SANS ISC Diary

Threat Score
90/100

Date Published: 2026-06-23

Date Updated: 2026-06-23

...
...

SonicWall disclosed CVE-2024-40766 (CVSS 9.3) affecting SSLVPN across Gen 5–7 appliances; despite patches, Akira and Fog ransomware operators and other attackers exploited patched devices through stale local accounts, overpermissive LDAP defaults, exposed Virtual Office Portals, and a MySonicWall backup compromise that leaked encrypted credentials, while a separate MFA bypass (CVE-2024-12802) and Gen 6 end-of-life further amplify risk — the report provides forensic indicators, detection rules, and a post-patch hardening checklist emphasizing account rotation, LDAP reconfiguration, portal access restriction, session termination, and upgrading to SonicOS 7.3.0+.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.