SonicWall SSL VPN Vulnerability CVE-2024-12802 Actively Exploited Despite Patching
Article Content
- •CVE-2024-12802 allows MFA bypass in SonicWall SSL VPN appliances.
- •Attackers exploited the vulnerability using brute-force methods without triggering alerts.
- •Gen6 devices require six additional steps for complete remediation post-patch.
A wave of attacks exploiting CVE-2024-12802, an authentication bypass vulnerability in SonicWall SSL VPN appliances, began in February 2026. Despite a firmware patch issued in 2025, attackers were able to bypass multifactor authentication (MFA) using brute-force techniques without triggering alerts. ReliaQuest identified multiple incidents where attackers accessed internal networks within minutes, deploying pre-ransomware tools. The vulnerability affects Gen6 devices, which require six additional manual reconfiguration steps for full remediation. SonicWall's advisory did not emphasize these steps, leading to a false sense of security among users. The flaw was rated 6.5 by SonicWall but assessed as critical (9.1) by CISA. The attacks are consistent with tactics used by the Akira ransomware group, which previously targeted SonicWall customers. Gen6 appliances reached end-of-life status on April 16, 2026, meaning they are no longer supported.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (8)
Following this threat?
Track Akira, Sonicwall and CVE-2024-12802 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Chinese Smishing Gang Targets Ireland and Four Other EU Countries Ireland is identified as one of five EU countries targeted by the Chinese text-scam group known as Smishing Triad, as reported by the EU cyber security agency Enisa. This group conducts large-scale smishing operations, which involve sending fraudulent text messages that impersonate legitimate organizations to steal…
Network Segmentation Failures Heighten Cyberattack Risks in 2026 Forescout's analysis of 47,700 network segments across 209 organizations reveals significant network segmentation failures, particularly involving IT, OT, IoT, and IoMT devices. The study found that 62% of segments contained only one device category, while 29% had two and 9% had three or more. Notably, only 13% of…