CVE-2024-12802Active Exploitation

MEDIUMCVSS 9.1 · CRITICAL

Exploitation observed; activity peaked at 11 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

SSL-VPN MFA Bypass in SonicWALL SSL-VPN can arise in specific cases due to the separate handling of UPN (User Principal Name) and SAM (Security Account Manager) account names when integrated with Microsoft Active Directory, allowing MFA to be configured independently for each login method and potentially enabling attackers to bypass MFA by exploiting the alternative account name.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-305

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Active exploitation appears in 19 classified signals
  • Patch or workaround signal is available
  • 31 mentions across 9 observed days
  • Momentum state: declining

What's happening

  • Active exploitation reported across 19 signals
  • Patch or workaround mentioned in 25 signals
  • Technical details provided in 25 signals
  • Disclosure: 3 classified signals
  • Peaked 6d ago at 11 mentions (2026-05-21); latest day: 3
  • 31 total mentions across 9 days

Deep dive

Activity timeline31 mentions / 9d
036811Mentions · 2026-05-19: 3Mentions · 2026-05-20: 4Mentions · 2026-05-21: 11Mentions · 2026-05-22: 4Mentions · 2026-05-26: 2Mentions · 2026-05-27: 2Mentions · 2026-05-28: 1Mentions · 2026-06-12: 1Mentions · 2026-06-23: 3Active Exploitation · 2026-05-19: 3Active Exploitation · 2026-05-20: 3Active Exploitation · 2026-05-21: 5Active Exploitation · 2026-05-22: 2Active Exploitation · 2026-05-26: 2Active Exploitation · 2026-05-28: 1Active Exploitation · 2026-06-23: 3Patch / Workaround · 2026-05-19: 3Patch / Workaround · 2026-05-20: 3Patch / Workaround · 2026-05-21: 7Patch / Workaround · 2026-05-22: 4Patch / Workaround · 2026-05-26: 2Patch / Workaround · 2026-05-27: 1Patch / Workaround · 2026-05-28: 1Patch / Workaround · 2026-06-12: 1Patch / Workaround · 2026-06-23: 3Technical Details · 2026-05-19: 3Technical Details · 2026-05-20: 3Technical Details · 2026-05-21: 9Technical Details · 2026-05-22: 3Technical Details · 2026-05-26: 2Technical Details · 2026-05-27: 1Technical Details · 2026-06-12: 1Technical Details · 2026-06-23: 305-1905-2005-2105-2205-2605-2705-2806-1206-23
Signal classification4 categories
Active Exploitation
1754.8%
Patch
929.0%
Disclosure
39.7%
General
26.5%
Referenced assets18 URLs
Classification over time
DateTotalLabels
2026-05-193
Active Exploitation3
2026-05-204
Active Exploitation3Patch1
2026-05-2111
Active Exploitation5Disclosure2General1Patch3
2026-05-224
Active Exploitation2Patch2
2026-05-262
Active Exploitation1Patch1
2026-05-272
General1Patch1
2026-05-281
Active Exploitation1
2026-06-121
Disclosure1
2026-06-233
Active Exploitation2Patch1
Full discourse20 posts
  • nuno almeida@_nunoalmeida_
    Patch

    "SonicWall warned in a security advisory for CVE-2024-12802 that installing the firmware update alone on Gen6 devices does not fully mitigate the vulnerability, and a manual reconfiguration of the LDAP server is required."

    Post summary

    SonicWall’s advisory for CVE‑2024‑12802 requires users to install the firmware update and additionally manually reconfigure the LDAP server to fully remediate the vulnerability.

    040512.4K
    365 followersView on X
  • Criminal IP@CriminalIP_US
    Patch

    🔐 SonicWall SSL-VPN MFA bypass: patched doesn’t always mean protected CVE-2024-12802 shows how exposed VPN devices can remain vulnerable even after firmware updates. Criminal IP findings: • ~6,250 internet-exposed SonicWall SSL-VPN assets • ~1,200 assets with expired SSL certificates • High-risk assets with multiple exposed services and vulnerabilities For Gen6 devices, firmware checks alone are not enough. Manual LDAP reconfiguration must also be verified. 🔎 Full analysis https://criminalip.io/knowledge-hub/blog/34923 #CyberSecurity #ThreatIntelligence #SonicWall #VPN #AttackSurface

    Post summary

    The post highlights that firmware patches alone do not secure SonicWall SSL‑VPN devices, emphasizing the need for manual LDAP reconfiguration and appearing to provide a workaround rather than a proof of concept or exploit.

    05020279
    4.9K followersView on X
  • Cyber News Live@cybernewslive
    Active Exploitation

    A hacking gang — likely Akira — has been silently bypassing the login protection on SonicWall VPN devices since February, even on devices where the patch was applied and multi-factor authentication appeared to be switched on. The flaw (CVE-2024-12802) lets attackers brute-force their way in without triggering any alerts. The patch alone does not fix the problem on older Gen6 devices — six additional manual steps are required, and those devices have now lost manufacturer support entirely. The systems behind these VPNs hold employee records, payroll, and internal business data at every organisation using them. ☠️ #CyberNewsLive https://cybersecuritydive.com/news/patch-bypass-hackers-exploit-flaw-sonicwall/820600/

    Post summary

    A hacking gang (Akira) is actively exploiting a login bypass flaw (CVE‑2024‑12802) on SonicWall VPNs, bypassing patch updates and MFA, and the fix requires additional manual steps on older devices.

    02021199
    2.0K followersView on X
  • ReliaQuest@ReliaQuest
    Active Exploitation

    Security teams patch fast. But patch status alone can still miss real exposure. In a new threat spotlight, ReliaQuest details what we assess with medium confidence to be the first in-the-wild exploitation of CVE-2024-12802 on SonicWall devices. What matters here: 🔹On Gen6 devices, the firmware patch alone does not fully remediate the issue 🔹Six manual reconfiguration steps are also required 🔹In the activity we observed, attackers brute-forced VPN accounts, bypassed MFA, and moved fast In one environment, the actor reached a file server within 30 minutes of initial access. In some cases, it took as few as 13 attempts to get a valid credential. This is where AI can help security teams close the gap between “patched” and “actually secure.” 🔗 Learn More: https://ow.ly/bf6x50Z1Iaz #ReliaQuest #ThreatResearch

    Post summary

    ReliaQuest reports the first in‑the‑wild exploitation of CVE‑2024‑12802 on SonicWall Gen6 devices, where attackers brute‑forced VPN credentials and bypassed MFA; firmware patches alone are insufficient, necessitating six manual reconfiguration steps.

    02030189
    2.6K followersView on X
  • DC3 DCISE@DC3DCISE
    Active Exploitation

    🔒ICYMI: Threat actors are bypassing Multi-Factor Authentication on #SonicWall Gen6 appliances due to incomplete patching of CVE-2024-12802.  Firmware updates alone are insufficient; manual LDAP reconfiguration is required.  Read more @BleepinComputer #CyberSecurity #VPN

    Post summary

    Threat actors are actively exploiting CVE‑2024‑12802 to bypass MFA on SonicWall Gen6 devices; firmware patches alone are insufficient and manual LDAP re‑configuration is needed.

    11020126
    734 followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    CVE-2024-40766 (CVSS 9.3) in SonicWall SSLVPN has been exploited by Akira and Fog ransomware since Sept 2024. Patching firmware is not remediation: stale accounts, broken LDAP config, and an exposed MFA enrollment portal are keeping patched firewalls wide open. Key findings: - Akira and Fog operators compromised SonicWall Gen 5/6/7 firewalls at scale, with encryption occurring in under 4 hours and some cases in 55 minutes. In Sept 2025 SonicWall confirmed the MySonicWall cloud platform was breached and all configuration backup files containing encrypted credentials were exposed. Any org with a MySonicWall account should treat its backup as compromised and rotate credentials now. - CVE-2024-12802 adds a second layer on Gen 6: a firmware patch alone does not fix this MFA bypass. Six manual LDAP reconfiguration steps from SNWLID-2025-0001 are required. Devices that looked patched by version were still fully exploitable. Gen 6 reached end-of-life April 16, 2026. No more patches are coming. - Across 14 audited firewalls: 12 had stale local accounts not in AD, including usernames with non-printable characters (a strong indicator of automated account creation by exploitation tooling). 11 had never rotated local passwords post-upgrade. 9 had the Default LDAP User Group granting implicit SSLVPN access to every AD account. - The Virtual Office Portal (MFA/TOTP enrollment) was internet-exposed on 7 of 14 firewalls. #DFIR_Radar

    Post summary

    CVE‑2024‑40766 is actively exploited by Akira and Fog ransomware; firmware patches alone do not remediate the issue, requiring manual LDAP reconfiguration and addressing stale accounts and exposed MFA portals.

    10110474
    1.7K followersView on X
  • DFIR Radar@DFIR_Radar
    Disclosure

    CVE-2024-12802 (CVSS 9.1) allows MFA bypass on SonicWall Gen6 SSL-VPN via UPN/SAM authentication path differences. Firmware patches alone insufficient - requires manual 6-step LDAP reconfiguration that standard patch workflows don't verify. #DFIR_Radar https://t.co/24eipizeUL

    Post summary

    The note highlights that CVE-2024-12802 is a high‑risk MFA bypass flaw in SonicWall Gen6 SSL‑VPN. It points out that firmware patches alone are insufficient and that a manual 6‑step LDAP reconfiguration is needed to fully remediate the vulnerability.

    11010188
    1.6K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    CVE-2024-12802 (CVSS 9.1) enables MFA bypass on SonicWall SSL-VPN via AD username format confusion. Gen6 devices require manual config changes beyond firmware patches. ReliaQuest confirms active exploitation Feb-Mar 2026. #DFIR_Radar https://t.co/PDE6lHFzdU

    Post summary

    The post reports active exploitation of CVE-2024-12802, notes its high severity and MFA bypass mechanism, and indicates vendor patches exist but require manual configuration changes.

    10020325
    1.8K followersView on X
  • ReliaQuest Threat Research@ReliaQuestTR
    Active Exploitation

    Between February and March 2026, we identified what we assess to be the first in-the-wild exploitation of CVE-2024-12802, an auth bypass in SonicWall SSL VPN that reduces security to single-factor even when MFA appears enabled. On Gen6 devices, patching the firmware isn't enough. Six manual LDAP reconfiguration steps are required, and standard patch workflows can't verify them. Devices showed as "patched" while remaining fully exploitable. Attackers brute-forced VPN credentials using automated tools and bypassed MFA silently with no failed login alert and no anomalous flag. In some cases it took as few as 13 attempts to land a valid credential. In one environment, the attacker went from VPN auth to file server to Cobalt Strike beacon and a BYOVD driver load in under 40 minutes. EDR stopped the payload, but the attacker adapted and started manually hunting for credentials through Notepad, a technique that blends right into normal file server activity. The pattern is consistent with initial access broker activity feeding into the ransomware ecosystem. The tools match TTPs seen in previous Akira-linked intrusions. Read our full analysis here 🔗 https://reliaquest.com/blog/threat-spotlight-vpn-exploitation-when-patched-doesnt-mean-protected/

    Post summary

    The passage reports the first real‑world exploitation of CVE‑2024‑12802 on SonicWall SSL VPN, detailing how attackers brute‑forced credentials, bypassed MFA, and noting that manual LDAP reconfiguration is required as a workaround.

    00030417
    7.6K followersView on X
  • Elusive@ElusivePrivacy
    Active Exploitation

    SonicWall VPN MFA Bypass SonicWall Gen6 SSL-VPN MFA is being bypassed in the wild not a new CVE, just incomplete patching. Attackers brute-force VPN credentials then bypass MFA on appliances where the CVE-2024-12802 fix was applied incompletely. Ransomware deployed within 30-60 minutes of access. Reliaquest tracking the campaign. Source: BleepingComputer / Reliaquest Full analysis → http://t.me/VulnerabilityNews Follow @VulnerabilityNw

    Post summary

    The post reports active exploitation of the SonicWall VPN MFA bypass in the wild, noting incomplete patching of CVE-2024-12802 and rapid ransomware deployment following credential brute‑force.

    11010130
    182 followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    CVE-2024-12802 allows MFA bypass on SonicWall Gen6 SSL-VPN appliances due to incomplete patching. ReliaQuest confirms active exploitation by access brokers deploying ransomware tools. Check logs for sess="CLI" indicator and event IDs 238/1080. #DFIR_Radar https://t.co/zTmPdKxwqd

    Post summary

    CVE-2024-12802 allows MFA bypass on SonicWall Gen6 SSL‑VPN appliances; ReliaQuest reports active exploitation by ransomware‑using access brokers, with log indicators sess="CLI" and event IDs 238/1080.

    10110165
    1.5K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-45659 2 - CVE-2026-5426 3 - CVE-2026-48172 4 - CVE-2024-12802 5 - CVE-2026-8945 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The tweet lists top trending CVEs without providing technical details, PoCs, or exploit information.

    00020150
    1.7K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    SonicWall Gen6 SSL-VPNでMFA回避 攻撃、CVE-2024-12802はファームウェア更新だけでは対策不十分 https://rocket-boys.co.jp/security-measures-lab/sonicwall-gen6-vpn-mfa-bypass-cve-2024-12802/ #セキュリティ対策Lab #security #securitynews

    Post summary

    The article notes that a firmware update alone is insufficient to mitigate the MFA‑bypass vulnerability CVE‑2024‑12802 on SonicWall Gen6 SSL‑VPN, highlighting the need for additional patches or workarounds.

    01001170
    407 followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    SonicWall Gen6 VPN authentication bypass (CVE-2024-12802) exploited in the wild despite patches - manual LDAP reconfiguration steps missed. ReliaQuest observed active ransomware-related intrusions exploiting this flaw across multiple organizations. Technical details: • CVE-2024-12802: MFA bypass due to separate UPN/SAM authentication handling in Active Directory integration • Firmware patches exist but require 6 additional manual LDAP reconfiguration steps often missed • Gen6 devices reached end-of-life April 2026, no future security updates available • Attackers brute-force VPN accounts (as few as 13 attempts), bypass MFA, lateral movement in <30 minutes Attack pattern observed: • Initial access via VPN credential brute-force leveraging UPN authentication path • Rapid lateral movement to domain-joined file servers via shared local admin passwords • Cobalt Strike beacon deployment and BYOVD attempts for EDR evasion • Initial access broker behavior: logout, return with different accounts for value assessment DFIR artifacts: • sess='CLI' in VPN authentication logs indicates scripted/automated authentication • Event IDs 238 and 1080 worth monitoring alongside VPN login anomalies • Successful MFA logs can be deceptive - authentication bypass still appears as normal MFA flow • VPN connections from VPS/VPN infrastructure vs expected user geolocations Hunt for sess='CLI' in SonicWall VPN logs combined with successful authentications for MFA-protected accounts. #DFIR_Radar

    Post summary

    CVE‑2024‑12802, a VPN MFA bypass, is actively exploited in the wild with attackers brute‑forcing credentials and moving laterally; firmware patches exist but manual steps are commonly missed.

    10010194
    1.8K followersView on X
  • CCB Alert@CCBalert
    Active Exploitation

    Warning: Critical, actively-exploited MFA Bypass in #SonicWall #SSL-VPN CVE-2024-12802 CVSS: 9.1 Follow all 6 manual reconfiguration steps for remediation on Gen6 devices and update firmware. For details, see: https://reliaquest.com/blog/threat-spotlight-vpn-exploitation-when-patched-doesnt-mean-protected/ #Patch #Patch #Patch

    Post summary

    CVE‑2024‑12802 is a critical MFA bypass in SonicWall SSL‑VPN that is actively exploited; remediation requires manual reconfiguration steps and firmware updates.

    02000204
    7.2K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    ReliaQuest warns that patching SonicWall Gen6 firmware leaves CVE-2024-12802 exploitable. Six manual LDAP configuration steps are required to stop MFA bypasses. https://securityexpress.info/hackers-exploit-hidden-sonicwall-vpn-flaw-to-bypass-mfa-silently/ https://t.co/1x7UG3I6vv

    Post summary

    ReliaQuest warns that patching SonicWall Gen6 firmware does not fully mitigate CVE‑2024‑12802 and requires six manual LDAP configuration steps to prevent MFA bypasses; no PoC, exploit code, or active exploitation is reported.

    00020339
    12.5K followersView on X
  • Marc-Frédéric Gomez@marcfredericgo
    Patch

    Ep.676 - RadioCSIRT Édition Française - Flash info Au sommaire de cette édition : 🔐 GnuPG corrige la CVE-2026-57062 dans gpgsm : l'analyse du format CMS accepte une longueur ICV de quatre octets au lieu des douze attendus pour AES-GCM, affaiblissant le contrôle d'intégrité. GnuPG jusqu'à 2.5.20 est concerné, en lien avec la CVE-2026-34182. CVSS 3.1 à 2.9. (CVEFeed / MITRE) 🐧 Le noyau Linux 7.1 est publié par Linus Torvalds le 14 juin 2026 : nouveau pilote NTFS en espace noyau (iomap, folios), Intel FRED activé par défaut, contrôles Landlock étendus aux sockets UNIX et suppression de plus de 140 000 lignes de code hérité. (Linux Journal) 🚨 Les agences Five Eyes publient une déclaration commune le 22 juin 2026 sur la transformation du risque cyber par l'intelligence artificielle : réduction de la fenêtre entre découverte et exploitation, appel à traiter le risque comme un enjeu métier, priorité aux fondamentaux et intégration de l'IA dans la défense. (CISA) 🔓 MISP Core corrige la CVE-2026-56423 : un défaut de contrôle d'accès dans les suppressions en masse permettait à un utilisateur contributeur de supprimer définitivement des Event Reports et Sharing Groups d'autres organisations à l'échelle de l'instance. Exploitable à distance. CVSS 3.1 HIGH à 9.4, CVSS 4.0 CRITICAL. (CVEFeed / CIRCL) 🛡️ Le SANS ISC détaille les configurations SonicWall vulnérables après correctif de la CVE-2024-40766 (CVSS 9.3, exploitée par Akira et Fog depuis septembre 2024) : comptes locaux obsolètes, mots de passe non renouvelés, groupe LDAP par défaut trop permissif, portail Virtual Office exposé permettant un contournement MFA. La CVE-2024-12802 vise le contournement MFA sur les équipements Gen 6 en fin de vie. (SANS Internet Storm Center) Pour écouter l'épisode: https://www.radiocsirt.org/podcast/ep-676-radiocsirt-edition-francaise-flash-info-cybersecurite-du-mardi-23-juin-2026/

    Post summary

    The release highlights several newly patched vulnerabilities, some of which have known active exploitation and includes technical details and mitigation guidance.

    00001111
    421 followersView on X
  • Decryption Digest ®@DecryptionDigst
    Active Exploitation

    SonicWall Gen6 SSL-VPN: firmware patch alone does not fix CVE-2024-12802 (CVSS 9.1). Akira operators reach file servers in 30 min. 6 LDAP steps required. http://decryptiondigest.com #SonicWall #CVE202412802 #Akira #MFABypass #PatchNow #CyberSecurity #InfoSec https://t.co/2fIdyrirgw

    Post summary

    The story highlights that a firmware patch does not mitigate SonicWall Gen6 SSL‑VPN CVE‑2024‑12802, with the Akira threat group reportedly exploiting it to reach file servers within 30 minutes via a 6‑step LDAP chain.

    0001066
    16 followersView on X
  • كاسبر سكاي@KasperskyDev
    Patch

    تحذير لمستخدمي SonicWall Gen6 SSL-VPN: الـ firmware patch لـ CVE-2024-12802 وحده لا يكفي. الثغرة تُتيح تجاوز MFA عبر UPN login format، والإصلاح يتطلب 6 خطوات LDAP يدوية إضافية غير مكتملة في أغلب البيئات. المهاجمون يصلون للشبكة الداخلية خلال 30 دقيقة. #SonicWall #Ransomware

    Post summary

    The notice warns that the firmware patch for CVE‑2024‑12802 alone is not enough, as the flaw permits MFA bypass through UPN login and attackers can reach the internal network within 30 minutes; additional LDAP steps are required to mitigate the vulnerability.

    10000147
    40.0K followersView on X
  • Arnav Sharma 🇦🇺@arnavsharma
    Patch

    SonicWall patch fallout hits APAC VPNs: CVE-2024-12802 exploits linger post-patch, mirroring the Aussie risk landscape. ACSC would flag Critical Infra risk; Essential Eight hinges on timely risk reduction, not patch one-off. Expect targeted APAC campaigns. #auscyber

    Post summary

    The post highlights that post‑patch exploits of CVE‑2024‑12802 persist on SonicWall APAC VPNs, urging timely risk reduction and warning of potential targeted campaigns.

    0001059
    2.2K followersView on X

Explore more