Akira ransomware activity continues to be linked to CVE-2024-40766, a critical improper access control vulnerability affecting SonicWall Gen5, Gen6, and Gen7 firewalls that was patched in August 2024. Rapid7 reported increasing exploitation, while ThreatDown’s MDR team associated recent incidents with the vulnerability without confirming exploitation in every case. Arctic Wolf previously reported increased Akira and Fog activity linked to SonicWall SSL VPN. Macnica’s historical research found that more than 100 of 218 organizations listed as Akira or Fog victims operated SonicWall devices—approximately 46%, compared with 5% or less among other ransomware groups’ victims—but characterized the exploitation evidence as circumstantial.
The continuing risk includes both unpatched devices and compromised credentials retained after patching. SonicWall investigations found attacks against patched appliances involving credentials carried over from older, vulnerable configurations without password resets. An August 2026 search identified 213,896 publicly reachable SonicWall VPN and management interfaces, but reachability alone does not establish vulnerability. Separately, Macnica estimated at least 48,933 exposed devices remained vulnerable in December 2024; that historical figure does not establish current exposure. Organizations should install the applicable SonicOS updates, reset local account passwords, remove inactive accounts, enforce SSL VPN multifactor authentication, limit privileges, and restrict and monitor management and Virtual Office Portal access. Patching alone may not address access enabled by previously compromised credentials.

See which actors are running it and whether you're in range.
12 events from the most recent confirmed update back to the earliest known activity.
A ThreatDown search identified 10,956 reachable SonicWall VPN portals and 202,940 management interfaces. Public reachability alone did not establish that any individual device was unpatched or exploitable.
An update to the joint Akira ransomware advisory stated that Akira threat actors had likely used CVE-2024-40766 for initial access.
A September 12 report described Rapid7's observation of increasing attacks exploiting CVE-2024-40766 following SonicWall's August warning. Rapid7 recommended software updates, local-account password rotation, removal of inactive accounts, SSLVPN multifactor authentication, and tighter portal access controls.
The Australian Cyber Security Centre warned that CVE-2024-40766 was being actively exploited.
SonicWall warned that Akira ransomware operators were exploiting CVE-2024-40766. The company urged users to install the available patch promptly.
SonicWall investigated attacks against patched appliances in 2025 and found that many involved credentials retained from older, vulnerable configurations without password resets.
Macnica estimated that at least 48,933 internet-exposed SonicWall devices remained unpatched against CVE-2024-40766 as of December 24. This represented approximately 13% of the assessed exposed population.
As of December 23, Macnica suspected that more than 100 organizations had been compromised by Akira and Fog through CVE-2024-40766. More than 100 of 218 examined victims operated SonicWall devices, but the research did not definitively establish exploitation.
CISA added the SonicWall vulnerability to its Known Exploited Vulnerabilities Catalog, identifying it as a vulnerability exploited in real-world attacks.
Macnica's research account states that the SonicWall NSA vulnerability CVE-2024-40766 was disclosed in September 2024.
SonicWall released a software fix for CVE-2024-40766, a critical improper access control vulnerability affecting SonicWall appliances. The vulnerability carries a CVSS score of 9.3 and is associated with VPN and management interfaces.
ThreatDown's MDR team handled multiple Akira ransomware cases in the weeks preceding its article, including incidents affecting two separate customers of one managed service provider. The team associated the overall pattern with CVE-2024-40766 but did not confirm exploitation in every individual case.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
threatdown.com
Open sourcesecurity.nl
Open sourcesecurity.macnica.co.jp
Open sourcearcticwolf.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.