
This SonicWall bug is 2 years old. Akira ransomware is still exploiting it.
No zero-day required. Just a patch left unapplied.
The Akira ransomware gang is still breaking into networks through a firewall bug SonicWall fixed two years ago. The critical vulnerability, CVE-2024-40766, carries a CVSS score of 9.3 out of 10. SonicWall published a fix in August 2024, but two years on, our MDR team has handled multiple Akira ransomware cases with a SonicWall device in the environment in just the past few weeks. Detections like this are on pace to run roughly 30% ahead of last year’s total by the time 2026 closes out.
A patch has existed for two years. It hasn’t slowed Akira down.
The gap is every device the patch never reached. Roughly 213,900 SonicWall VPN and management interfaces are reachable from the public internet right now.
MDR ties the pattern (not each case individually) to CVE-2024-40766, and it isn’t alone in that read: the Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities Catalog in September 2024, and updated its joint Akira ransomware advisory in November 2025 to state that Akira threat actors have likely used it for initial access.
SonicWall hasn’t disclosed much information about the flaw publicly, other than to say that it is an improper access control vulnerability requiring a software fix and, unusually, to advise affected customers to reset passwords for locally managed SSLVPN accounts in addition to patching.
In 2025, SonicWall investigated attacks against patched appliances and found that many involved credentials carried over from older, vulnerable configurations without being reset. The reach isn’t limited to one organization at a time, either. One MSP turned up in our case data twice, hit through two separate customer environments.
Roughly 213,900 SonicWall interfaces are reachable right now
On August 24, 2026, a ThreatDown search found roughly 213,900 SonicWall VPN and management interfaces reachable from the public internet — the exact two components SonicWall’s own advisory ties to this vulnerability. Reachable isn’t the same as vulnerable, but it represents a vast potential attack surface for Akira to explore.
| Search | What it captures | Reachable instances |
|---|---|---|
| “Server: SonicWALL SSL-VPN Web Server” | VPN portals | 10,956 |
| “Server: SonicWALL” (excluding SSL-VPN) | Management interfaces | 202,940 |
| Combined | Total reachable | 213,896 |
This doesn’t confirm any single device is unpatched or exploitable, only how much of the surface sits in plain view, including to threat actors.
The Mythos effect
Akira’s routine weaponization of a two-year-old critical vulnerability is just the latest in a long list of examples of ransomware groups exploiting organizations’ inability to apply security patches in a timely manner.
For cybercriminals, the longer the gap between security patches being published and being applied, the better. Unfortunately, for organizations that struggle to stay on top of their patch management, that gap is about to widen significantly because of AI.
In a July 2026 blog post, Windows Executive Vice President Pavan Davuluri wrote that as AI helps defenders find more issues, customers will see a higher volume of security updates in every release. The change is already showing up in the numbers: Microsoft’s May Patch Tuesday fixed 120 vulnerabilities, in June that figured climbed to 200, and in July, that jumped to a record-breaking 570, with Microsoft pointing to AI as the reason.

Call this the “Mythos effect.” The capacity to apply patches doesn’t scale just because the number of patches does. Ten times the fixes doesn’t mean ten times the people available to apply them. And that gap doesn’t stay flat: it compounds. Every release adds to a “patch debt” that teams already submerged in never fully pay down, so the backlog only grows.
A single, two-year-old, publicly documented bug is already sustaining an active ransomware campaign. That’s patch debt playing out in real time. AI-accelerated vulnerability discovery is about to make it far more common.
As the patch queue compounds, another AI-enabled danger is looming. As assessed in our recent report, Cybercrime in the age of AI, the Mythos-class AI that’s fueling the increase in vulnerability discovery is likely to reach criminal marketplaces in a matter of months. When it does, the same acceleration reshaping defenders’ patch queues turns into an offensive automation tool for criminals, capable of discovering and chaining together vulnerabilities.
Patch like the clock is running
The fix for the SonicWall vulnerability has existed for two years. Update to SonicOS 7.3.0 or later, reset local account passwords (especially on devices migrated from Gen 6), enforce MFA across every VPN and admin portal, and restrict management access to trusted networks only. None of it is complicated. What’s hard is doing it consistently, on every device, before Akira finds the one that got missed.
AI is reshaping this fight on both sides at once: faster vulnerability discovery for defenders, and soon, faster exploitation for attackers.
Campaigns like this one live in the gap between the two. ThreatDown Patch Management, delivered through your ThreatDown console, closes that gap at the point most organizations actually lose it: getting the fix onto every device, not just knowing one exists. What gets through anyway is exactly what ThreatDown MDR exists to catch.
20
26Cybercrime in the Age of AI
AI is rewiring the cybercrime ecosystem.
You have six months to prepare.
20
26Cybercrime in the Age of AI
AI is rewiring the cybercrime ecosystem.
You have six months to prepare.