IT Brief Ireland - Technology news for CIOs & IT decision-makers
Ireland
Akira exploits two-year-old SonicWall flaw, ThreatDown says

Akira exploits two-year-old SonicWall flaw, ThreatDown says

Wed, 23rd Sep 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Akira ransomware operators are continuing to exploit a SonicWall vulnerability that was fixed two years ago, according to ThreatDown. The security company linked the activity to CVE-2024-40766, which has a CVSS score of 9.3 out of 10.

The finding highlights a familiar cybersecurity problem: attackers still succeed with old flaws when patches are not fully applied. ThreatDown said its managed detection and response team had handled multiple Akira ransomware cases involving SonicWall devices in recent weeks, and detections are on track to finish about 30% above last year's total by the end of 2026.

SonicWall issued a fix for CVE-2024-40766 in August 2024. ThreatDown said the weakness affects SonicWall VPN and management interfaces and remains useful to Akira because many internet-facing systems still expose those services.

In ThreatDown's research, about 213,900 SonicWall VPN and management interfaces were reachable from the public internet at the time of its search. That total included 10,956 VPN portals identified through the "SonicWALL SSL-VPN Web Server" banner and 202,940 management interfaces identified through "SonicWALL" banners excluding SSL-VPN.

Internet exposure does not prove a device is vulnerable or unpatched, ThreatDown noted. But the size of the visible footprint gives ransomware groups a large pool of potential targets to probe.

The US Cybersecurity and Infrastructure Security Agency added CVE-2024-40766 to its Known Exploited Vulnerabilities Catalog in 2024. It later updated a joint advisory on Akira ransomware to say the group had likely used the flaw for initial access.

Public information from SonicWall on the bug has been limited. ThreatDown said the vendor described it as an improper access control vulnerability and took the unusual step of advising customers to reset passwords for locally managed SSLVPN accounts as well as apply the software fix.

That advice appears to matter beyond patching alone. In 2025, SonicWall investigated attacks on patched appliances and found that many cases involved credentials carried over from older, vulnerable configurations without password resets.

Repeat intrusions

ThreatDown said the pattern was not limited to isolated incidents. Its case data showed one managed service provider was hit twice through two separate customer environments using the same legacy route.

That suggests the issue can spread across service relationships where providers oversee multiple customer estates, especially if older device settings or account practices remain in place after software updates. It also underlines the operational risk for managed service providers, which can become an entry point into more than one downstream network.

The report places the SonicWall activity in a broader discussion about patching pressure on corporate IT teams. ThreatDown argued that the volume of security updates is increasing and that many organisations are building up what it called "patch debt", where backlogs grow faster than staff can clear them.

It linked that trend to the effect of artificial intelligence on vulnerability discovery. The report cited comments from Microsoft that customers should expect a higher volume of security updates as AI helps defenders identify more flaws, and pointed to a sharp rise this year in the number of vulnerabilities fixed in monthly Windows updates.

L. Travis, author of the research, wrote: "A patch has existed for two years. It hasn't slowed Akira down. The gap is every device the patch never reached."

Defensive steps

ThreatDown said organisations using affected SonicWall systems should update to SonicOS 7.3.0 or later, reset local account passwords, enforce multi-factor authentication across VPN and administrative portals, and restrict management access to trusted networks. It added that password resets were especially important on devices migrated from older Gen 6 systems.

The central point of the research is that well-known vulnerabilities can remain productive for ransomware groups long after vendors issue a fix. In this case, Akira does not need a zero-day exploit when older security gaps and inherited credentials are still present on exposed systems, ThreatDown argued.

Travis wrote: "A single, two-year-old, publicly documented bug is already sustaining an active ransomware campaign. That's patch debt playing out in real time."