Critical severity9.8CISA KEVNVD Advisory· Published Aug 23, 2024· Updated Jun 17, 2026
CVE-2024-40766
CVE-2024-40766
Description
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.
Affected products
4- Range: <=7.0.1-5035
Patches
Vulnerability mechanics
References
2- psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0015nvdVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
4- Ransomware Groups Increasingly Deploy EDR Kill TechniquesInfosecurity Magazine · Jul 27, 2026
- CVE-2026-15409, CVE-2026-15410: SonicWall SMA 1000 zero-day vulnerabilities exploited in the wildTenable Blog · Jul 15, 2026
- CVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration., (Tue, Jun 23rd)SANS Internet Storm Center · Jun 23, 2026
- Ransomware Tactics, Techniques, and Procedures in a Shifting Threat LandscapeMandiant Threat Intelligence · Mar 16, 2026