CVE-2024-40766 Exploited by Ransomware Groups Targeting SonicWall Firewalls

CVE-2024-40766 Exploited by Ransomware Groups Targeting SonicWall Firewalls

4h ago Isc.Sans.Edunvd.nist.gov 82% similarity 74.0
Share:

Article Content

Browse articles
ThreatCluster

CVE-2024-40766 is an improper access control vulnerability in SonicWall SonicOS affecting Gen 5, Gen 6, and Gen 7 firewalls. The vulnerability, with a CVSS score of 9.3, allows unauthorized access and can crash the device. SonicWall serves approximately 500,000 businesses, many of which lack dedicated security teams. Ransomware groups Akira and Fog have exploited this vulnerability since September 2024, with significant compromises reported. By December 2024, nearly 49,000 devices were still publicly exposed and unpatched. Dwell times for attacks have been alarmingly short, with encryption occurring in under four hours in many cases. SonicWall's MySonicWall platform was also breached, exposing configuration backups and encrypted credentials. The exploitation has escalated in 2026, with ongoing attacks reported.

Key Points: • CVE-2024-40766 affects SonicWall firewalls, allowing unauthorized access and potential crashes. • Over 48,000 devices remain unpatched, making them prime targets for ransomware groups. • The MySonicWall breach has compromised configuration backups, increasing vulnerability.

ThreatCluster AI

Timeline

2024-08-23
CVE-2024-40766 published
SonicWall disclosed an improper access control vulnerability in SonicOS affecting multiple firewall generations.
Isc.Sans.Edu
2024-09-01
Exploitation by Akira reported
Arctic Wolf reported that Akira affiliates began compromising SSLVPN accounts on vulnerable SonicWall devices.
Isc.Sans.Edu
2024-09-09
CVE added to CISA KEV
CISA added CVE-2024-40766 to its Known Exploited Vulnerabilities Catalog due to active exploitation.
nvd.nist.gov
2025-01-09
CVE-2024-12802 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-10-01
SonicWall MySonicWall breach confirmed
SonicWall confirmed that attackers accessed all configuration backup files, affecting all MySonicWall accounts.
Isc.Sans.Edu
2026-06-23
Ongoing exploitation in 2026
Reports indicate that exploitation of CVE-2024-40766 continues, with significant ransomware activity targeting SonicWall devices.
Isc.Sans.Edu

Community

Browse all →