CybersecurityAugust 10, 2026· via BleepingComputer

SonicWall flaws exploited by ransomware gangs, CISA warns

SonicWall flaws exploited by ransomware gangs, CISA warns

Image : BleepingComputer

Ransomware gangs are now weaponizing two recently patched flaws in SonicWall’s SMA1000 series appliances, including a critical server-side request forgery (SSRF) vulnerability that can let attackers bypass authentication and gain full control over unpatched devices. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added both issues to its Known Exploited Vulnerabilities catalog, signaling active exploitation in the wild and urging organizations to apply fixes immediately.

A widening attack surface

The vulnerabilities—CVE-2024-40766 (SSRF with a CVSS score of 10) and CVE-2024-40767 (a high-severity path traversal flaw)—affect SonicWall SMA 1000 series devices running specific firmware versions. CISA’s advisory follows reports from security researchers and incident responders who observed ransomware operators scanning for vulnerable endpoints shortly after proof-of-concept exploits were published last month. While SonicWall issued patches in late July, many organizations have yet to deploy them, leaving exposed gateways as low-hanging fruit for intruders.

Why delayed patching is a gamble

The timing of this campaign underscores a persistent gap between vulnerability disclosure and remediation. Security teams often deprioritize appliance updates due to downtime risks or misplaced confidence in perimeter defenses. Yet the SMA1000 series serves as a critical remote access gateway for many enterprises, making it a prime target for initial access brokers who sell footholds to ransomware groups. Once inside, attackers can move laterally, exfiltrate data, or deploy file-encrypting malware.

A call to action for admins

CISA’s inclusion of these flaws in its catalog triggers federal requirements for civilian agencies to patch within deadlines, but private-sector organizations should treat this as an urgent directive, not a suggestion. SonicWall users are advised to verify their firmware versions and apply the latest updates, then audit logs for signs of compromise such as unexpected authentication requests or unusual outbound traffic patterns. Given the SSRF flaw’s severity, organizations may also consider temporary network isolation for unpatched devices until updates are confirmed.

Why it matters

The active exploitation of SMA1000 vulnerabilities highlights how quickly ransomware groups pivot from proof-of-concept to real-world attacks. For enterprises, the lesson is clear: appliance updates are not a checkbox but a continuous defense priority. Failing to patch promptly can turn a single gateway into the entry point for a full-scale breach, with consequences ranging from data loss to regulatory penalties. In an era where remote access is ubiquitous, delaying fixes is no longer an option—it’s an open invitation to attackers.


Source: BleepingComputer. AI-assisted editorial synthesis — TechnoExpress.

Read the original source on BleepingComputer →

← Back to home