CVE-2024-40766Active Exploitation(sonicwall / nsa_2650)

HIGHCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 10 mentions and remains active

Immediate actions

  • Patch sonicwall nsa_2650 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.

6.3/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-09-30. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-284

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nsa_2650
  • nsa_2700
  • nsa_3600
  • nsa_3650

Threat summary

  • Active exploitation appears in 14 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 21 mentions across 11 observed days

What's happening

  • Active exploitation reported across 14 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 12 signals
  • Technical details provided in 9 signals
  • General: 1 classified signal
  • Peaked 9d ago at 10 mentions (2026-06-23); latest day: 1
  • 21 total mentions across 11 days

Affected systems

Vendors
Products
nsa_2650nsa_2700nsa_3600nsa_3650nsa_3700nsa_4600nsa_4650nsa_4700nsa_5600nsa_5650

1 version affected across 52 products

Deep dive

Activity timeline21 mentions / 11d
035810Mentions · 2026-03-06: 1Mentions · 2026-06-23: 10Mentions · 2026-06-26: 1Mentions · 2026-06-27: 2Mentions · 2026-07-02: 1Mentions · 2026-07-12: 1Mentions · 2026-09-04: 1Mentions · 2026-09-10: 1Mentions · 2026-09-28: 1Mentions · 2026-10-01: 1Mentions · 2026-10-05: 1PoC Mentioned / Linked · 2026-09-10: 1Active Exploitation · 2026-06-23: 8Active Exploitation · 2026-06-26: 1Active Exploitation · 2026-06-27: 1Active Exploitation · 2026-07-02: 1Active Exploitation · 2026-07-12: 1Active Exploitation · 2026-09-04: 1Active Exploitation · 2026-09-10: 1Patch / Workaround · 2026-03-06: 1Patch / Workaround · 2026-06-23: 7Patch / Workaround · 2026-06-27: 2Patch / Workaround · 2026-07-02: 1Patch / Workaround · 2026-09-10: 1Technical Details · 2026-06-23: 6Technical Details · 2026-06-27: 1Technical Details · 2026-07-02: 1Technical Details · 2026-09-04: 103-0606-2306-2606-2707-0207-1209-0409-1009-2810-0110-05
Signal classification3 categories
Active Exploitation
1161.1%
Patch
633.3%
General
15.6%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-03-061
Patch1
2026-06-2310
Active Exploitation6Patch4
2026-06-261
Active Exploitation1
2026-06-272
General1Patch1
2026-07-021
Active Exploitation1
2026-07-121
Active Exploitation1
2026-09-041
Active Exploitation1
2026-09-101
Active Exploitation1
Full discourse20 posts
  • DFIR Radar@DFIR_Radar
    General

    DFIR Weekly Recap | This week brought zero-days, supply chain hits, and persistent access campaigns across nearly every layer of the enterprise stack. - CVE-2024-40766: SonicWall patch closed the bug but misconfigured devices stayed exposed. - Turla's STOCKSTAY expands the Russian 🇷🇺 group's intelligence-gathering toolset. - CVE-2026-33017 Langflow flaw weaponized to drop a Monero cryptominer. - VBScript campaign uses WhatsApp to distribute RMM software for stealthy access. - CVE-2026-20245 zero-day actively exploited in Cisco Catalyst SD-WAN Manager. - Klue supply chain attackdetectable through artifacts left in Salesforce instances. - Photo ZIP phishing hits hospitality sector, delivering a Node.js implant for persistence. - netlogon.log captures Kerberos authentication detail that Event 1644 simply misses. - StealC and Amadey expose the layered cybercrime-as-a-service economy behind infostealer delivery. - Payouts King ransomware broker deploys new Edgecution malware as an initial access tool. Top stories in the thread below. #DFIR_Radar

    Post summary

    A weekly summary covering multiple CVEs, noting patch availability for one, active exploitation of another, and various other emerging threats with limited technical detail.

    10011451
    1.7K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    CVE-2024-40766 (CVSS 9.3) in SonicWall SSLVPN has been exploited by Akira and Fog ransomware since Sept 2024. Patching firmware is not remediation: stale accounts, broken LDAP config, and an exposed MFA enrollment portal are keeping patched firewalls wide open. Key findings: - Akira and Fog operators compromised SonicWall Gen 5/6/7 firewalls at scale, with encryption occurring in under 4 hours and some cases in 55 minutes. In Sept 2025 SonicWall confirmed the MySonicWall cloud platform was breached and all configuration backup files containing encrypted credentials were exposed. Any org with a MySonicWall account should treat its backup as compromised and rotate credentials now. - CVE-2024-12802 adds a second layer on Gen 6: a firmware patch alone does not fix this MFA bypass. Six manual LDAP reconfiguration steps from SNWLID-2025-0001 are required. Devices that looked patched by version were still fully exploitable. Gen 6 reached end-of-life April 16, 2026. No more patches are coming. - Across 14 audited firewalls: 12 had stale local accounts not in AD, including usernames with non-printable characters (a strong indicator of automated account creation by exploitation tooling). 11 had never rotated local passwords post-upgrade. 9 had the Default LDAP User Group granting implicit SSLVPN access to every AD account. - The Virtual Office Portal (MFA/TOTP enrollment) was internet-exposed on 7 of 14 firewalls. #DFIR_Radar

    Post summary

    The post confirms active exploitation of CVE‑2024‑40766 by ransomware actors, highlights inadequacies of firmware patches, and advises manual mitigation steps.

    10110474
    1.7K followersView on X
  • ThreatCluster@threatcluster
    Active Exploitation

    Ransomware groups Akira and Fog have exploited CVE-2024-40766 in SonicWall SonicOS firewalls since September 2024, with nearly 49,000 vulnerable devices exposed publicly as of December 2024, http://Isc.Sans.Edu reported. #Ransomware #Vulnerability https://t.co/UtbedyaMpp

    Post summary

    Ransomware groups Akira and Fog have been exploiting CVE-2024-40766 in SonicWall SonicOS firewalls since September 2024, affecting nearly 49,000 publicly exposed devices as of December 2024.

    10010187
    396 followersView on X
  • ThreatCluster@threatcluster
    Active Exploitation

    Akira ransomware operators exploited CVE-2024-40766 via SSL VPNs on SonicWall Gen 7 firewalls, breaching networks and pivoting to domain controllers, Bitdefender and Huntress reported. #Vulnerability #InfoSec https://t.co/ZyPVJmnHp9

    Post summary

    Akira ransomware operators exploited CVE-2024-40766 on SonicWall Gen 7 firewalls via SSL VPN, with observed network breach and pivoting to domain controllers, as reported by Bitdefender and Huntress.

    10010126
    396 followersView on X
  • ThreatDown@Threat_Down
    Active Exploitation

    Sonic's whole thing is speed. Akira didn't even need to hustle. 🦔 213,900 SonicWall interfaces are reachable right now, the same components tied to CVE-2024-40766. A fix has existed for two years, but Akira is still getting in. Patch it. https://bit.ly/4xgqpfu

    Post summary

    SonicWall interfaces are reportedly exposed and actively exploited by Akira for CVE‑2024‑40766; patching is urgently recommended.

    00010567
    18.0K followersView on X
  • Gagan Suie@gagansuie
    Active Exploitation

    How do you pass an OTP prompt you cannot see? Researchers assess the operators are replaying stolen OTP seeds, most likely harvested from earlier exploitation of CVE-2024-40766. Steal the seed, generate the codes forever.

    Post summary

    The text indicates that CVE-2024-40766 is actively exploited by operators using stolen OTP seeds, but provides no technical details, PoC, or patch information.

    1000044
    193 followersView on X
  • DFIR Radar@DFIR_Radar
    Patch

    📌 CVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration., (Tue, Jun 23rd)

    Post summary

    The tweet announces that CVE-2024-40766 has been patched, noting that the underlying configuration remains unfixed.

    10000107
    1.7K followersView on X
  • Marc-Frédéric Gomez@marcfredericgo
    Patch

    Ep.676 - RadioCSIRT Édition Française - Flash info Au sommaire de cette édition : 🔐 GnuPG corrige la CVE-2026-57062 dans gpgsm : l'analyse du format CMS accepte une longueur ICV de quatre octets au lieu des douze attendus pour AES-GCM, affaiblissant le contrôle d'intégrité. GnuPG jusqu'à 2.5.20 est concerné, en lien avec la CVE-2026-34182. CVSS 3.1 à 2.9. (CVEFeed / MITRE) 🐧 Le noyau Linux 7.1 est publié par Linus Torvalds le 14 juin 2026 : nouveau pilote NTFS en espace noyau (iomap, folios), Intel FRED activé par défaut, contrôles Landlock étendus aux sockets UNIX et suppression de plus de 140 000 lignes de code hérité. (Linux Journal) 🚨 Les agences Five Eyes publient une déclaration commune le 22 juin 2026 sur la transformation du risque cyber par l'intelligence artificielle : réduction de la fenêtre entre découverte et exploitation, appel à traiter le risque comme un enjeu métier, priorité aux fondamentaux et intégration de l'IA dans la défense. (CISA) 🔓 MISP Core corrige la CVE-2026-56423 : un défaut de contrôle d'accès dans les suppressions en masse permettait à un utilisateur contributeur de supprimer définitivement des Event Reports et Sharing Groups d'autres organisations à l'échelle de l'instance. Exploitable à distance. CVSS 3.1 HIGH à 9.4, CVSS 4.0 CRITICAL. (CVEFeed / CIRCL) 🛡️ Le SANS ISC détaille les configurations SonicWall vulnérables après correctif de la CVE-2024-40766 (CVSS 9.3, exploitée par Akira et Fog depuis septembre 2024) : comptes locaux obsolètes, mots de passe non renouvelés, groupe LDAP par défaut trop permissif, portail Virtual Office exposé permettant un contournement MFA. La CVE-2024-12802 vise le contournement MFA sur les équipements Gen 6 en fin de vie. (SANS Internet Storm Center) Pour écouter l'épisode: https://www.radiocsirt.org/podcast/ep-676-radiocsirt-edition-francaise-flash-info-cybersecurite-du-mardi-23-juin-2026/

    Post summary

    The episode highlights new patches for GnuPG and MISP Core, discusses configuration fixes after a CVE‑2024‑40766 patch, and notes that this vulnerability is being actively exploited by Akira and Fog.

    00001111
    421 followersView on X
  • Rahmi Demir ⭐⭐⭐⭐⭐@rahmid3mir
    Active Exploitation

    🚨 #GüvenlikBülteni #SiberGüvenlik: SonicWall Güvenlik Duvarlarında Kritik Yetkisiz Erişim Riski (CVE-2024-40766) Bülten Tarihi: 23 Haziran 2026 Referans: CVE-2024-40766 / CISA KEV Etkilenen Cihazlar: SonicWall Gen 5, Gen 6 ve Gen 7 (SonicOS 7.0.1-5035 ve altı) Etki Seviyesi: KRİTİK (Yetkisiz Erişim / Kimlik Doğrulama Atlama - CVSS: 9.3) SonicWall SonicOS'ta bulunan kritik bir güvenlik açığının fidye yazılımı grupları tarafından aktif olarak istismar edildiği bildirildi. Uzmanlar, yalnızca yama uygulamanın yeterli olmayabileceği konusunda uyarıyor. 📌 Ne Oluyor? CVE-2024-40766, yönetim arayüzleri ve SSLVPN servislerindeki erişim kontrolü eksikliğinden kaynaklanıyor. Saldırganlar, internete açık yönetim panelleri veya VPN servisleri üzerinden yetkisiz erişim sağlamaya çalışabiliyor. ⚠️ Riskler Neler? • Yetkisiz erişim girişimleri • SSLVPN hesaplarının hedef alınması • MFA korumalarının aşılması • Fidye yazılımı saldırıları • Ağ kaynaklarının ele geçirilmesi Araştırmalara göre #Akira ve #Fog grupları bu açığı aktif olarak kullanıyor. 🛡️ Alınabilecek Önlemler 1️⃣ SonicOS'u güncel sürüme yükseltin. 2️⃣ Yönetim arayüzlerini internet erişimine kapatın. 3️⃣ SSLVPN erişimlerini IP kısıtlamalarıyla sınırlandırın. 4️⃣ VPN loglarını düzenli inceleyin. 5️⃣ EOL durumundaki Gen 6 cihazları değiştirin. 📊 Neden Önemli? Bu açık, fidye yazılımı operasyonlarında ilk erişim noktası olarak kullanılıyor. İnternete açık güvenlik duvarları kurumsal ağlar için ciddi risk oluşturuyor. 🔚 Sonuç SonicWall kullanan kurumların yalnızca yamalara değil, erişim politikaları ve cihaz sıkılaştırmalarına da odaklanması gerekiyor.

    Post summary

    SonicWall devices are facing a critical unauthenticated access vulnerability (CVE-2024-40766) that ransomware groups are actively exploiting; administrators must apply patches and enforce stricter access controls.

    0001051
    335 followersView on X
  • MoveWorth@MoveWorth

    A security update without a clear owner can become a ransomware entry point. Microsoft reported: “In September 2025, Microsoft tracked a four-week surge in Akira ransomware across 50+ organizations—mostly small and medium-sized businesses—tied to CVE-2024-40766 (SonicWall SSL VPN exploitation).” Source: Microsoft Digital Defense Report 2026, published October 5, 2026. The problem isn’t always a lack of security tools. It’s often a lack of structure. When updates are managed separately, it can be hard to see which system is exposed, who’s responsible for patching it, and whether the work was finished. Think of a repair bench where every piece of equipment needs a service tag. If an urgent tag gets buried or has no assigned owner, the equipment can return to service with the problem still inside. Our security protocol work brings those tags into one practical system: a complete inventory, clear ownership, urgency rankings, documented update routines, and a dashboard that tracks completion. See how clearer patch ownership can strengthen your digital foundation. Visit http://moveworth.com #Cybersecurity #SmallBusinessSecurity #DigitalInfrastructure #SystemsBeforeGrowth #TurnUpYourDigital

    0000056
    37 followersView on X
  • ♫Why♥Not♪@Python_s_

    NØØT Security Alerts Classification: Critical CVE: CVE-2024-40766 Product: SonicWall / SonicOS Summary: VulnCheck reports real-world exploitation activity affecting SonicWall / SonicOS. Evidence: Ransomware use confirmed; Active exploitation reported; Severe impact class Impact: The vulnerability is associated with ransomware activity and may contribute to compromise of exposed systems. Action: Prioritize vendor remediation, identify exposed affected systems, and investigate for evidence of exploitation when applicable. Date: 23 Apr 2024 Source: https://vulncheck.com/ #NØØT #CyberSecurity #InfoSec #ThreatIntelligence #CyberThreats #CVE #CyberDefense #SonicWall #SonicOS #CVE_2024_40766 #ActiveExploitation #Exploit #Ransomware #RansomwareAttack

    0000052
    226 followersView on X
  • SHELLCODE@sh3ll_c0d3

    ⏱️ 90 MINUTES TO BLACKOUT: Fog Ransomware on SonicWall! 🌫️💻 Adversaries weaponize SonicOS CVE-2024-40766 to breach perimeters & encrypt VMware ESXi VMDKs in 90 min. 👉 Analysis: https://sh3llc0d3.com/blog/fog-ransomware-weaponizes-sonicwall-ssl-vpn-vulnerability-cve-2024-40766-rapid-90-minute-intrusions-leading-to-esxi-hypervisor-encryption/ #sh3llc0d3 #shellcode #Ransomware #SonicWall #ESXi

    00000116
    108 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    Attackers are chaining CVE-2024-40766 and CVE-2024-29014 to achieve unauthenticated RCE on SonicWall SMA 1000 appliances. Following edge device compromise, threat actors pivot into internal network segments and establish persistent C2 channels. Runtime segmentation can help limit blast radius from compromised network infrastructure. #ZeroDay #CloudSecurity :link: Full breakdown: https://aviatrix.ai/threat-research-center/sonicwall-sma1000-cve-2026-83548-cve-2026-83549-zero-days-actively-exploited

    Post summary

    The text reports that attackers are actively exploiting CVE-2024-40766 and CVE-2024-29014 to gain unauthenticated RCE on SonicWall SMA 1000 devices, subsequently pivoting into internal networks and establishing persistent command‑and‑control channels.

    0000028
    2.0K followersView on X
  • @pedri77@pedri77
    Active Exploitation

    A SANS audit of 14 patched SonicWall firewalls shows Akira ransomware still getting in via stale accounts and LDAP misconfigurations the firmware update never touched. SonicWall CVE-2024-40766 Proves Patching Is Not Rem... https://f.mtr.cool/koakeembxl

    Post summary

    The SANS audit shows that, despite firmware updates, 14 patched SonicWall firewalls remain vulnerable to Akira ransomware via stale accounts and LDAP misconfigurations, confirming ongoing exploitation of CVE‑2024‑40766.

    0000067
    2.1K followersView on X
  • Meridian Group@MeridianEU
    Active Exploitation

    CVE-2024-40766 in #SonicWall firewalls actively exploited for persistent unauthorized access. Threat actors establish rogue accounts, harvest credentials, and enroll malicious TOTP devices within compromised environments to maintain long-term network access. https://t.co/fbERXRPHMl

    Post summary

    The tweet reports that CVE-2024-40766 is being actively exploited on SonicWall firewalls, with attackers creating rogue accounts and enrolling malicious TOTP devices to maintain persistent network access.

    0000053
    63 followersView on X
  • MiGuεl CaRvAjAl ®@miguelcarvajalm
    Patch

    #SonicWall CVE-2024-40766 Proves #Patching Is Not Remediation https://latesthackingnews.com/2026/06/23/sonicwall-cve-2024-40766-patching-not-enough/

    Post summary

    The tweet merely references SonicWall CVE‑2024‑40766 and claims that patching is insufficient, without disclosing any concrete PoC, exploit, or technical details.

    0000040
    433 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows ransomware groups exploiting CVE-2024-40766 in SonicWall SSL VPNs to achieve data encryption within 55 minutes of initial compromise. Attackers leverage VPN access for persistent C2 and lateral movement through compromised credentials. Runtime segmentation can help contain post-compromise pivoting across network segments. #ZeroTrust #Vulnerability 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/cve-2024-40766-sonicwall-ransomware-exploitation

    Post summary

    Ransomware operators are actively exploiting CVE‑2024‑40766 on SonicWall SSL VPNs to encrypt data swiftly, using VPN access for persistence and lateral movement, with runtime segmentation suggested as a countermeasure.

    0000069
    1.9K followersView on X
  • Shah Sheikh@shah_sheikh
    Patch

    SonicWall CVE-2024-40766 Proves Patching Is Not Remediation: A SANS audit of 14 patched SonicWall firewalls shows Akira ransomware still getting in via stale accounts and LDAP misconfigurations the firmware update never touched. SonicWall… https://latesthackingnews.com/2026/06/23/sonicwall-cve-2024-40766-patching-not-enough/?utm_source=dlvr.it&utm_medium=twitter https://t.co/Ma8VzuiZ71

    Post summary

    The article demonstrates that firmware patching alone is insufficient, as Akira ransomware still penetrated 14 patched SonicWall firewalls via stale accounts and LDAP misconfigurations omitted from the update.

    0000057
    2.3K followersView on X
  • CyberNewsDaily@NewsDaily18579
    Active Exploitation

    🔴 Critical CVE-2024-40766 (CVSS: N/A) [CISA KEV: ACTIVELY EXPLOITED] [EPSS: 15.7%]: A vulnerability was patched but still exploited because misconfigured systems weren't fixed. via SANS ISC https://t.co/jOkFMknPJo

    Post summary

    CVE‑2024‑40766 is actively exploited in the wild despite an existing patch, as reported by SANS ISC due to misconfigured systems.

    0000042
    14 followersView on X
  • UNDERCODE NEWS@UndercodeNews
    Patch

    🚨 #CVE-2024-40766: The Patch Was Installed The Breach Path Remained Open + Video -Fact Checker: ✅: 3 ❌: 2 || 3/5 → Score: 60% ⚖️ -Prediction: 📈 3 Positive | 📉 3 Negative http://undercodenews.com/cve-2024-40766-the-patch-was-installed-the-breach-path-remained-open-video/

    Post summary

    The post highlights that a patch for CVE-2024-40766 has been installed, yet notes that the breach path remains open, indicating potential limitations or residual risk.

    0000030
    953 followersView on X
CPE platform detail52 entries

52 of 52 entries

PartVendorProductVersionTarget SWTarget HW
HWsonicwallnsa_2650---
HWsonicwallnsa_2700---
HWsonicwallnsa_3600---
HWsonicwallnsa_3650---
HWsonicwallnsa_3700---
HWsonicwallnsa_4600---
HWsonicwallnsa_4650---
HWsonicwallnsa_4700---
HWsonicwallnsa_5600---
HWsonicwallnsa_5650---
HWsonicwallnsa_5700---
HWsonicwallnsa_6600---
HWsonicwallnsa_6650---
HWsonicwallnsa_6700---
HWsonicwallnssp_10700---
HWsonicwallnssp_11700---
HWsonicwallnssp_12400---
HWsonicwallnssp_12800---
HWsonicwallnssp_13700---
HWsonicwallsm9800---
HWsonicwallsm_9200---
HWsonicwallsm_9250---
HWsonicwallsm_9400---
HWsonicwallsm_9450---
HWsonicwallsm_9600---
HWsonicwallsm_9650---
HWsonicwallsoho---
HWsonicwallsoho_250---
HWsonicwallsoho_250w---
HWsonicwallsohow---
OSsonicwallsonicos---
HWsonicwalltz270---
HWsonicwalltz270w---
HWsonicwalltz370---
HWsonicwalltz370w---
HWsonicwalltz470---
HWsonicwalltz470w---
HWsonicwalltz570---
HWsonicwalltz570p---
HWsonicwalltz570w---
HWsonicwalltz670---
HWsonicwalltz_300---
HWsonicwalltz_300p---
HWsonicwalltz_300w---
HWsonicwalltz_350---
HWsonicwalltz_350w---
HWsonicwalltz_400---
HWsonicwalltz_400w---
HWsonicwalltz_500---
HWsonicwalltz_500w---
HWsonicwalltz_600---
HWsonicwalltz_600p---

Explore more