Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
CVE-2024-40766 is an improper access control vulnerability in SonicWall SonicOS affecting Gen 5, Gen 6, and Gen 7 firewalls. The vulnerability, with a CVSS score of 9.3, allows unauthorized access and can crash the device. SonicWall serves approximately 500,000 businesses, many of which lack dedicat...
A wave of attacks exploiting CVE-2024-12802, an authentication bypass vulnerability in SonicWall SSL VPN appliances, began in February 2026. Despite a firmware patch issued in 2025, attackers were able to bypass multifactor authentication (MFA) using brute-force techniques without triggering alerts....
On May 19, 2026, Microsoft disrupted Fox Tempest, a malware-signing-as-a-service (MSaaS) operation that provided over 1,000 fraudulent code-signing certificates to cybercriminals, enabling them to disguise malware as legitimate software. The operation, active since May 2025, abused Microsoft's Artif...