logo

ACSC Warns Of SonicWall SSL VPN Exploit (CVE-2024-40766)

ID: 79320358-6ba7-5cc2-b6f9-2e1aa0d8a806

STIX ID: report--79320358-6ba7-5cc2-b6f9-2e1aa0d8a806

Feed Name: Cyble Blog

Threat Score
80/100

Date Published: 2025-10-21

Date Updated: 2026-07-16

...
...

## Executive summary The Australian Cyber Security Centre (ACSC) and SonicWall warn of active exploitation of CVE-2024-40766 — a critical access-control bypass in SonicWall SSL VPN appliances (CVSS 9.3) — being used in the wild, including by actors deploying Akira ransomware; affected Gen5–Gen7 devices require urgent firmware updates, credential resets, MFA and access hardening, and organizations should apply provided mitigations and block identified IoCs immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.