Akira ransomware affiliates continue breaching organizations via SonicWall firewalls
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-40766 | Improper Access Control in SonicWall SonicOS Management (Gen 5/6/7 Firewalls) CVE-2024-40766 is an improper access control flaw (CWE-284) in SonicWall SonicOS management access that can allow unauthorized access to protected resources and, under specific conditions, crash the affected firewall. It is network-exploitable without privileges or user interaction per its CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N) and affects Gen 5 and Gen 6 appliances as well as Gen 7 devices running SonicOS 7.0.1-5035 or older. A successful attacker gains unauthorized access to resources behind or on the appliance and can potentially take the firewall offline, creating opportunities for follow-on attacks such as VPN account compromise and ransomware deployment. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-09 with known ransomware use, and recent reporting ties Akira ransomware activity — including MFA bypass on SonicWall VPNs affecting over 100 accounts — to this legacy bug combined with password reuse. No public PoC is known, but EPSS assigns an ~18.2% probability of exploitation within 30 days (97th percentile). Do: Upgrade Gen 7 appliances to SonicOS 7.0.1-5037 or later (the fixed release beyond the affected 7.0.1-5035) and move Gen 5/6 devices to the latest SonicOS release SonicWall supports for those generations; per CISA KEV guidance, apply vendor mitigations or discontinue use if patching is not possible. Restrict WAN-side management and SSLVPN access to trusted sources, audit VPN accounts for password reuse, rotate credentials and any locally stored recovery codes, and review logs for signs of Akira-related compromise such as MFA bypass or disabled EDR agents. | 9.8 | 18% | KEV ransomware |
| mass≈100,000–500,000 internet-exposed SonicWall firewalls/SSLVPN endpoints (installed base of 1M+ appliances) |
Full article480 words · extracted from helpnetsecurity.com · click to collapse
Over a year after SonicWall patched CVE-2024-40766, a critical flaw in its next-gen firewalls, ransomware attackers are still gaining a foothold in organizations by exploiting it.
Like last September and earlier this year, the attackers are affiliates of the Akira ransomware-as-a-service outfit.
The July 2025 surge in attacks was, according to SonicWall, facilitated by the fact that organizations has migrated from Gen 6 to Gen 7 firewalls but did not reset local user passwords (as advised by the firewall maker).
This time around, Akira affiliates are also leveraging other firewall-related “tricks”.
“Since [early August 2025], the Rapid7 Incident Response team has observed an uptick in intrusions involving SonicWall appliances,” Rapid7 has shared on Wednesday, and said that evidence they collected suggests that the Akira group might be using a combination of three separate security risks to gain unauthorized access and conduct ransomware operations.
The first one is CVE-2024-40766, still unpatched on some systems.
The second one stems from a misconfiguration in the device’s SSLVPN Default Users Group setting.
“This setting automatically adds every successfully authenticated LDAP user to a predefined local group, regardless of their actual membership in Active Directory. If that default group has access to sensitive services – such as SSL VPN, administrative interfaces, or unrestricted network zones – then any compromised AD account, even one with no legitimate need for those services, will instantly inherit those permissions,” SonicWall explains.
“This effectively bypasses intended AD group-based access controls, giving attackers a direct path into the network perimeter as soon as they obtain valid credentials.”
The third one is the Virtual Office Portal hosted by SonicWall appliances, which the attackers have been accessing and using to configure MFA/TOTP on previously compromised user accounts.
What to do?
The Australian Cyber Security Centre has also warned about an recent uptick in Akira attacks agains vulerable Australian organizations via CVE-2024-40766.
According to Rapid7’s responders, the group’s affiliates continued with their tried and true modus operandi: they gain intial access via the SSLVPN component, escalate privileges to an elevated account or service account, find and exfiltrate sensitive files from network shares or file servers, delete and/or stop backups, and finally deploy the ransomware at the hypervisor level.
Organizations using SonicWall firewalls should rotate passwords on all SonicWall local accounts and remove those that are unused and configure MFA/TOTP policies for SonicWall SSLVPN services, Rapid7 advises.
They should also:
- Set the Default LDAP User Group to “None”
- Make sure that the Virtual Office Portal is only accessible from trusted (local) networks and monitor access to it
- Ensure all SonicWall appliances are running on the latest patch
As noted by SonicWall last month, the recently released SonicOS version 7.3.0 also includes enhanced protections against brute force attacks and additional MFA controls.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/09/11/akira-ransomware-sonicwall-firewalls/