Key Takeaways

  • Akira ransomware operators continue to exploit CVE-2024-40766, despite SonicWall fixing the critical flaw in August 2024.
  • Researchers identified approximately 213,896 publicly reachable SonicWall VPN and management interfaces on 24 August 2026.
  • Patching alone may leave organizations exposed when local passwords remain unchanged, MFA is absent, or administrative interfaces are internet-facing.

A two-year-old SonicWall vulnerability remains a viable entry point for Akira ransomware operators, showing how slowly enterprise exposure can shrink even after a vendor releases a fix. The immediate concern is not simply that some appliances remain unpatched. Systems running updated software may still carry compromised or reusable credentials from an earlier intrusion attempt.

The vulnerability, CVE-2024-40766, affects SonicWall VPN and management interfaces and has a CVSS score of 9.3 out of 10, according to SecurityBrief Australia. SonicWall fixed the flaw in August 2024, and CISA added it to its Known Exploited Vulnerabilities catalog the following month. CISA later confirmed that Akira actors likely used it to gain initial access.

That history gives security teams a clear signal: this is not a theoretical weakness discovered in a lab. Attackers have had time to study the affected infrastructure, refine their techniques, and locate organizations that missed one or more remediation steps.

The scale of public exposure remains striking. ThreatDown reported approximately 213,896 SonicWall VPN and management interfaces reachable from the public internet on 24 August 2026. That figure does not mean every interface is vulnerable or compromised. It does, however, illustrate the large pool of systems attackers can scan, fingerprint, and test.

Applying a firmware update closes the software flaw, but it does not automatically invalidate credentials that may already have been stolen. If an attacker obtained a local SonicWall account before patching, that account could remain useful afterward. Related reporting points to Microsoft Active Directory credentials as a factor in maintaining access and moving deeper into affected environments.

ThreatDown said its managed-detection-and-response team handled multiple recent Akira cases involving SonicWall devices. The company projects that its 2026 detections will finish approximately 30% above 2025 levels. That trajectory suggests older edge-device flaws can continue producing fresh incidents long after they disappear from the daily vulnerability news cycle.

Why do these weaknesses linger? Edge appliances are often treated differently from servers and endpoints. They may sit outside routine identity-governance processes, use local accounts that receive little attention, or expose administrative services for remote support. Ownership can also be fragmented among networking teams, managed service providers, and security operations. A patch can be recorded as complete while password resets, access reviews, and configuration changes remain open.

The broader incident data supports that concern. ENISA recorded vulnerability exploitation as the initial-access vector in 21.3% of nearly 4,900 EU incidents analyzed from July 2024 through June 2025. Akira accounted for 11.6% of the ransomware variants observed during that period. Exploitation and Akira both occupy documented, recurring portions of the threat landscape rather than appearing as isolated anomalies.

For business leaders, the operational lesson extends beyond SonicWall. Patch status is one control, not a complete measure of recovery. Organizations can reduce exposure by upgrading affected appliances to SonicOS 7.3.0 or later, resetting local-account passwords, enforcing MFA, and limiting administrative interfaces to trusted networks. Teams should also review authentication logs for unusual source addresses, repeated failures, and successful access at unexpected times.

A sensible response includes checking whether an affected device was exposed before it was patched. If it was, credential rotation and investigation are necessary steps to ensure the network is actually secure, rather than simply treating the software update as the end of the incident. Security teams can use actively exploited vulnerability information to prioritize work, while broader risk programs assign clear ownership for internet-facing appliances.

Akira does not need a new vulnerability when an older one still opens doors. Reducing that opportunity requires patching, identity cleanup, exposure management, and post-remediation validation to work together, especially around VPN gateways and firewall administration services.