CVE-2024-40766

CVSS 9.8 · CRITICAL
Used in ransomware
Known ransomware association per CISA
Exploited in the wild
Remediation overdue by 725 days
EPSS p96
Higher than 96% of all CVEs — imminent exploitation likely.
Patch available
Vendor advisory or patch linked

Published 8/23/2024 · updated 6/17/2026 · CWE-284

Share
Get asset-aware triage

Summary

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.

CVSS 9.8 — CRITICAL

9.8 / 10
  • AV: Network
  • AC: Low complexity
  • PR: No privileges
  • UI: No user interaction
  • S: Scope unchanged
  • C: Confidentiality: High
  • I: Integrity: High
  • A: Availability: High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS exploitation probability

15.7%

Percentile p96 — Higher than 96% of all CVEs — imminent exploitation likely.

Affected products

1 vendor/product entries
  • Sonicwall Sonicos< 5.9.2.14-13o
Do you run any of these? Sign in to match this CVE against your SBOM and asset inventory automatically.

Timeline

  1. Aug 23, 2024 · Disclosed / published in NVD
  2. Sep 9, 2024 · Added to CISA KEV catalog
  3. Sep 30, 2024 · CISA remediation deadline
  4. Jun 17, 2026 · Intel last updated

Intel sources

Which upstream feeds returned data for this CVE, and when they were last fetched.

  • NVD· 94 days ago
  • CVE.org· 79 days ago
  • FIRST EPSS· 94 days ago
  • CISA KEV· 12 days ago
  • OSV· 94 days ago

Listed in CISA KEV

Added 2024-09-09 · Remediation overdue by 725 days · used in known ransomware campaigns.

References

Unlock the full report

See how CVE-2024-40766 hits your stack.

Free public data ends here. Sign in to correlate this CVE against your SBOM and assets, get an AI-grounded exploit chain, generate a ModSecurity virtual patch, and share findings with your team.

  • · Asset-aware CVSS & priority
  • · Grounded AI analysis (A–D graded)
  • · Auto-generated WAF / IPS rules
  • · Jira, SIEM, Slack, Teams delivery

No credit card · 100 free enrichments · analyst-grade citations.