The vulnerability, assigned a CVSS score of 9.3, affects SonicWall’s VPN and administrative portals. ThreatDown’s managed detection and response team has observed a surge in Akira‑related incidents involving SonicWall devices, with detections projected to end 2026 at roughly 30 % higher than the previous year’s total.
SonicWall released a software fix for CVE‑2024‑40766 in August 2024, but ThreatDown’s research found that about 213,900 SonicWall VPN and management interfaces remained reachable from the public internet at the time of its scan. The exposure included 10,956 VPN portals identified by the “SonicWALL SSL‑VPN Web Server” banner and 202,940 management interfaces flagged by generic “SonicWALL” banners.
While internet exposure does not guarantee a device is unpatched, the large visible footprint provides ransomware groups with a sizable pool of potential targets. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities Catalog in 2024 and later noted that Akira likely used it for initial compromise in a joint advisory.
SonicWall’s public guidance on the bug described it as an improper access‑control issue and unusually advised customers to reset passwords for locally managed SSL‑VPN accounts in addition to applying the software update. ThreatDown says the advice is critical because many post‑patch attacks in 2025 involved credentials carried over from older configurations that were never reset.
The pattern is not isolated. ThreatDown’s data show a managed service provider hit twice through separate customer environments using the same legacy route, illustrating how outdated device settings can cascade across service relationships. This underscores the operational risk for MSPs that oversee multiple client networks.
The findings feed a broader discussion about “patch debt,” a term ThreatDown uses to describe the growing backlog of security updates that outpaces IT staff capacity. The firm links the trend to artificial‑intelligence‑driven vulnerability discovery, noting that vendors like Microsoft expect a higher volume of patches as AI aids defenders in identifying flaws.
To mitigate the ongoing risk, ThreatDown recommends that organizations running affected SonicWall appliances upgrade to SonicOS 7.3.0 or later, reset all local account passwords, enforce multi‑factor authentication on VPN and admin portals, and restrict management access to trusted networks, especially for devices migrated from older Generation 6 systems.