Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yes. In September 2025, government agencies and incident responders linked Akira ransomware intrusions to vulnerable SonicWall SSL VPN access, including CVE-2024-40766. That is the date of the reported surge—not evidence of a new Akira surge in September 2026. Organizations using SonicWall firewalls should check the current, model-specific vendor guidance, update affected devices, and address credentials as directed.

Is Akira ransomware targeting SonicWall firewalls?

Akira activity involving SonicWall SSL VPNs was reported in September 2025. The Australian Cyber Security Centre said it was aware of Akira targeting vulnerable Australian organizations through SonicWall SSL VPNs. A joint government advisory later said Akira actors had likely used CVE-2024-40766 for initial access.

CyberScoop’s September 12, 2025 report described the activity as a fresh surge. It quoted Rapid7’s incident-response team: “In the vast majority of cases our team is working, the SonicWall firewalls have been upgraded to a version that patches CVE-2024-40766.” That observation refers to cases Rapid7 was handling, not all SonicWall firewalls or all victims. The cited reporting does not establish a new surge in September 2026.

Sources: Australian Cyber Security Centre alert; Rapid7 incident-response report; joint #StopRansomware advisory; CyberScoop report, September 12, 2025.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
SonicWall TZ470 Network Security/Firewall Appliance
  • The latest SonicWall TZ470 series, are the first desktop form factor nextgeneration firewalls (NGFW) with 1 or 5 Gigabit Ethernet interfaces. The series consist of a wide range of products to suit a variety of use cases.
  • Reduce complexity and get the business running without relying on IT personnel with easy onboarding using SonicExpress App and Zero-Touch Deployment, and easy management through a single pane of glass
  • Drive business growth by investing in next-gen appliances with multi-gigabit and advanced security features, to future-proof against the changing network and security landscape
  • Ensure seamless communication as stores talk to HQ via easy VPN connectivity which allows IT administrators to create a hub and spoke configuration for the safe transport of data between all locations
  • Hardware: Operating system: SonicOS 7. | Interfaces: 8x1GbE, 2x1GbE, 2 USB 3., 1 Console | Management: Network Security Manager, CLI, SSH, Web UI, GMS, REST APIs | VLAN interfaces: 128 | Access points supported (maximum): 32

Which SonicWall devices are affected by CVE-2024-40766?

The Australian Cyber Security Centre’s September 10, 2025 alert described the affected scope as including Gen 5 and Gen 6 devices, and Gen 7 devices running SonicOS 7.0.1-5035 or older. It said CVE-2024-40766 can enable unauthorized access and, in specific conditions, cause a firewall crash.

This is dated guidance, not a substitute for checking your exact appliance and firmware against SonicWall’s current advisory. Confirm applicability and the prescribed update and response steps with the vendor before acting. The available reporting does not establish that every SonicWall model or firmware version is affected.

Source: Australian Cyber Security Centre alert.

How can an Akira intrusion progress after VPN access?

Rapid7 described an observed pattern in which attackers gained initial access through SSL VPN, escalated privileges, stole sensitive files from network shares or file servers, interfered with backups, and deployed ransomware at the hypervisor level. This is a sequence reported in incidents, not a guaranteed playbook for every Akira intrusion.

Rank #2
SonicWall TZ270W Wireless Gen7 Firewall | SMB Wi-Fi Security Appliance with 2 Gbps Firewall Speed, Integrated Wireless Radios, Threat Protection, and Cloud Management (02-SSC-2823)
  • SonicWall TZ270W Appliance Only - No Service Subscription (02-SSC-2823) - Combines enterprise-grade firewalling with integrated 802.11ac Wave 2 Wi-Fi to deliver secure wired and wireless connectivity in one compact device for small offices and clinics.
  • Blocks zero-day threats and ransomware with Capture ATP sandboxing enhanced by RTDMI, plus IPS and anti-malware scanning for layered protection.
  • Eliminates the need for separate access points in smaller spaces thanks to built-in high-speed wireless that is simple to deploy and manage.
  • Supports VPN, SD-WAN, and TLS 1.3 decryption to secure hybrid cloud access and remote workers while maintaining usability and performance.
  • Delivers gigabit performance with up to 750,000 concurrent connections to handle growth in users, devices, and SaaS applications.

Because the reported activity can reach beyond the firewall, suspected unauthorized VPN access warrants attention to identity systems, endpoints, servers, network shares, and backup infrastructure—not just the edge device. Preserve relevant evidence and involve qualified incident responders if your organization cannot investigate safely and thoroughly in-house.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Source: Rapid7 incident-response report.

What should administrators do after updating a SonicWall firewall?

Follow the vendor’s current device-specific remediation guidance. The Australian Cyber Security Centre says SonicWall urged organizations to change passwords after updating, and warns that organizations may remain vulnerable if they have not fully implemented mitigation, including updating credentials after firmware updates. A firmware update alone should not be assumed to complete remediation.

  1. Identify the SonicWall model and installed firmware, then check the current SonicWall advisory for CVE-2024-40766 for applicable updates and response instructions.
  2. Apply the vendor-prescribed update and mitigation steps for the specific device.
  3. Update passwords and credentials as directed by SonicWall, including after the firmware update where the vendor instructs.
  4. If compromise is suspected, preserve firewall, VPN, identity, endpoint, server, and backup evidence and seek qualified incident-response support before routine cleanup destroys useful evidence.

Sources: Australian Cyber Security Centre alert; SonicWall product security notice.

Rank #3
Sonicwall NSA 2700 (02-SSC-4324)
  • The SonicWall Network Security appliance (NSa) Mid-Range Firewall is next-generation security designed specifically for businesses of 250 users and up.
  • Secure Remote Workers - SonicWall NetExtender provides an intuitive SSL-VPN connection client that’s easy to deploy and configure. Easily provide your remote workers with secure access to your corporate network from Linux, Mac and Windows devices.
  • Built-in Wireless Controller - Implement high-speed wireless security by combining a NSa Series next-generation firewall with a SonicWall SonicWave wireless access point. NSa Series firewalls and SonicWave access points both feature 2.5 GbE ports that enable multi-gigabit wireless throughput offered in Wave 2 wireless technology.
  • With cloud-based and on-box capabilities like TLS/SSL decryption and inspection, application intelligence and control, secure SD-WAN, real-time visualization, and WLAN management, SonicWall provides flexible, fast and cost-effective security to keep the threats out and your business thriving.
  • Highlights: 1 RU – Form Factor | 16 x 1 GbE interfaces | 3 x 10 GbE interfaces | 2 Gbps Threat and Malware Analysis Throughput | Enterprise Internet Edge Ready
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Was the SonicWall cloud-backup incident connected to Akira?

SonicWall said its investigation into a 2025 cloud-backup security incident found it unrelated to Akira attacks on firewalls and other edge devices. The incident concerned access to configuration backup files in a specific cloud environment; it should not be conflated with the reported Akira intrusions through vulnerable SSL VPNs.

Source: SonicWall, November 4, 2025.

How does the September 2026 SMA1000 advisory differ?

The Canadian Centre for Cyber Security’s September 2, 2026 advisory concerns CVE-2026-83548 and CVE-2026-83549 in specified SonicWall SMA1000 appliances: models 6210, 7210, and 8200v running listed older platform-hotfix versions. The advisory says SonicWall indicated exploitation. These are separate vulnerabilities in a separate product family; the advisory does not connect them to the 2025 Akira/CVE-2024-40766 reporting.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Administrators of those SMA1000 models should consult the advisory and SonicWall’s device-specific guidance rather than treating this as part of the Akira firewall surge.

Source: Canadian Centre for Cyber Security advisory AV26-872, September 2, 2026.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.