isc.sans.edu 6/23/2026, 4:11:05 AM · external

CVE-2024-40766 exposes SonicWall firewalls to ransomware

CVE-2024-40766 exposes SonicWall firewalls to ransomware
CyberSIXT Evidence Panel
CISA KEV Listed in KEV
Patch Patch Available
Threat Actor

THE article discusses CVE-2024-40766, a severe vulnerability in SonicWall's SonicOS affecting firewall access controls. Despite patches being available, many organizations fail to implement essential post-patch configurations, leaving themselves vulnerable to exploitation by ransomware groups, particularly Akira and Fog. Key issues identified include stale local accounts, unrotated passwords, and misconfigured LDAP default user groups, which could grant excessive access rights.

Additionally, the exposure of the Virtual Office Portal allows attackers to bypass multi-factor authentication (MFA). The article concludes with a strong recommendation for organizations to conduct thorough audits, update configurations, and follow a checklist for remediation to secure their systems effectively.

View Primary Source Via isc.sans.edu

Article by CyberSIXT