• News/
  • https://www.bleepingcomputer.com/news/security/akira-ransomware-exploiting-critical-sonicwall-sslvpn-bug-again/

Akira ransomware exploiting critical SonicWall SSLVPN bug again

BleepingComputer
·
Bill Toulas
·
Published Sep 11, 2025
·
Updated

The Akira ransomware gang is actively exploiting CVE-2024-40766, a year-old critical-severity access control vulnerability, to gain unauthorized access to SonicWall devices. The hackers are leverging the security issue to gain access to target networks via unpatched SonicWall SSL VPN endpoints. SonicWall released a patch for CVE-2024-40766 last year in August, marking it as actively exploited. The flaw allows unauthorized resource access and can cause firewall crashes. At the time, SonicWall strongly recommended that applying the update should be accompanied by a password reset for users with locally managed SSLVPN accounts. Without rotating the passwords after the update, threat actors could use exposed credentials for valid accounts to configure the multi-factor authentication (MFA) or time-based one-time sassword (TOTP) system and gain access. Akira was among the first ransomware groups to actively exploit it in starting September 2024. An alert from the Australian Cyber Security Center (ACSC) yesterday warns organizations of the new malicious activity, urging immediate action. “ASD’s ACSC is aware of a recent increase in active exploitation in Australia of a 2024 critical vulnerability in SonicWall SSL VPNs (CVE-2024-40766),” reads the  advisory. “We are aware of the Akira ransomware targeting vulnerable Australian organizations through SonicWall SSL VPNs,” says the Australian Cyber Security Centre. Cybersecurity firm Rapid7 has made similar observations, reporting that ...

Read full article

Affected Software

1 affected component
SonicWall SSL VPN

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the Akira ransomware gang exploiting a critical vulnerability in SonicWall SSLVPN.

2

What security implications are discussed?

The security implications involve unauthorized access to SonicWall devices due to a critical access control vulnerability.

3

What specific vulnerability is being exploited?

The vulnerability being exploited is identified as CVE-2024-40766, which is a year-old critical-severity issue.

4

Who is the group responsible for the ransomware attacks?

The Akira ransomware gang is responsible for the attacks taking advantage of the SonicWall SSLVPN vulnerability.

5

What products or software are affected by the ransomware attacks?

The affected software includes SonicWall SSL VPN devices.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203