CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

VPN Exploitation When Patched Doesn't Mean Protected

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2118

As cited

Copy frozen at (site build).

vulnerabilities

VPN Exploitation When Patched Doesn't Mean Protected

CVE-2024-12802 is an authentication bypass vulnerability in SonicWall SSL VPN appliances that reduces security to single-factor authentication and bypasses MFA. On Gen6 devices, the firmware patch alone does not remediate the vulnerability; six additional manual reconfiguration steps are required, yet standard patch management workflows do not verify these steps, leaving devices appearing patched while remaining exploitable. ReliaQuest identified in-the-wild exploitation of this vulnerability between February and March 2026, where threat actors brute-forced VPN credentials and deployed ransomware staging tools within 30 minutes of initial access.

Why it matters: Organizations running SonicWall Gen6 SSL VPN appliances are at immediate risk if they patched based on firmware version alone without completing six manual remediation steps; practitioners should verify all required configuration changes and implement detection for the sess="CLI" session type to identify brute-force attacks early before ransomware actors gain network access.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

VPN Exploitation When Patched Doesn't Mean Protected

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

VPN Exploitation When Patched Doesn't Mean Protected

ReliaQuest identified exploitation of CVE-2024-12802, an authentication bypass in SonicWall SSL virtual private network (VPN) appliances, between February and March 2026. On Gen6 devices, the firmware patch alone does not remediate the vulnerability; six additional manual reconfiguration steps are required, leaving patched devices fully exploitable. Attackers brute-forced VPN credentials and bypassed multifactor authentication (MFA) to gain internal network access, with some intrusions deploying ransomware staging tools within 30 minutes of initial access.

Why it matters: Organizations running SonicWall Gen6 appliances are at risk if they relied on firmware patching alone to remediate CVE-2024-12802, as the vulnerability remains exploitable without manual reconfiguration steps; immediate verification of all six Gen6 remediation steps and monitoring for the sess='CLI' session type in VPN logs are required to detect and block active exploitation.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

VPN Exploitation When Patched Doesn't Mean Protected

ReliaQuest identified exploitation of CVE-2024-12802, an authentication bypass in SonicWall SSL virtual private network (VPN) appliances, between February and March 2026. On Gen6 devices, the firmware patch alone does not remediate the vulnerability; six additional manual reconfiguration steps are required, leaving patched devices fully exploitable. Attackers brute-forced VPN credentials and bypassed multifactor authentication (MFA) to gain internal network access, with some intrusions deploying ransomware staging tools within 30 minutes of initial access.

Why it matters: Organizations running SonicWall Gen6 appliances are at risk if they relied on firmware patching alone to remediate CVE-2024-12802, as the vulnerability remains exploitable without manual reconfiguration steps; immediate verification of all six Gen6 remediation steps and monitoring for the sess='CLI' session type in VPN logs are required to detect and block active exploitation.

VendorsSonicWall
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary