The Akira ransomware gang is actively exploiting CVE-2024-40766, a year-old critical-severity access control vulnerability, to gain unauthorized access to SonicWall devices. The hackers are leverging the security issue to gain access to target networks via unpatched SonicWall SSL VPN endpoints. SonicWall released a patch for CVE-2024-40766 last year in August, marking it as actively exploited. The flaw allows unauthorized resource access and can cause firewall crashes. At the time, SonicWall strongly recommended that applying the update should be accompanied by a password reset for users with locally managed SSLVPN accounts. Without rotating the passwords after the update, threat actors could use exposed credentials for valid accounts to configure the multi-factor authentication (MFA) or time-based one-time sassword (TOTP) system and gain access. Akira was among the first ransomware groups to actively exploit it in starting September 2024. An alert from the Australian Cyber Security Center (ACSC) yesterday warns organizations of the new malicious activity, urging immediate action. “ASD’s ACSC is aware of a recent increase in active exploitation in Australia of a 2024 critical vulnerability in SonicWall SSL VPNs (CVE-2024-40766),” reads the advisory. “We are aware of the Akira ransomware targeting vulnerable Australian organizations through SonicWall SSL VPNs,” says the Australian Cyber Security Centre. Cybersecurity firm Rapid7 has made similar observations, reporting that ...
Akira ransomware exploiting critical SonicWall SSLVPN bug again
BleepingComputer
·Bill Toulas
·Published Sep 11, 2025
·Updated
Affected Software
1 affected component
SonicWall SSL VPN
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the Akira ransomware gang exploiting a critical vulnerability in SonicWall SSLVPN.
2
What security implications are discussed?
The security implications involve unauthorized access to SonicWall devices due to a critical access control vulnerability.
3
What specific vulnerability is being exploited?
The vulnerability being exploited is identified as CVE-2024-40766, which is a year-old critical-severity issue.
4
Who is the group responsible for the ransomware attacks?
The Akira ransomware gang is responsible for the attacks taking advantage of the SonicWall SSLVPN vulnerability.
5
What products or software are affected by the ransomware attacks?
The affected software includes SonicWall SSL VPN devices.