CVE-2024-12802
CVSS 9.1 CRITICAL: sSL-VPN MFA Bypass in SonicWALL SSL-VPN can arise in specific cases due to the separate handling of UPN (User… EPSS 0.5% (40th percentile).
Vulnerabilities & Exploits · Credential Theft
The broken assumption is that a firmware update means the VPN is safe. On SonicWall Gen6 SSL-VPN appliances, that is not true: devices can show as patched and still leave MFA bypassable until the LDAP server is manually reconfigured.
ReliaQuest says it has now seen the first in-the-wild exploitation of CVE-2024-12802 across multiple environments. SonicWall’s advisory says the firmware update alone does not fully mitigate Gen6 devices; Gen7 and Gen8 are not affected in the same way, and the issue matters because attackers used the access for internal recon and credential reuse before moving toward ransomware staging.
The forward risk is a false clean bill of health. Teams that stop at firmware verification may leave a working VPN foothold in place, and that access can be used to test reused credentials and reach internal systems even after the appliance reports as updated.
2 sources · May 20
CVSS 9.1 CRITICAL: sSL-VPN MFA Bypass in SonicWALL SSL-VPN can arise in specific cases due to the separate handling of UPN (User… EPSS 0.5% (40th percentile).
BleepingComputer
Hackers bypass SonicWall VPN MFA due to incomplete patching
Threat actors brute-forced VPN credentials and bypassed multi-factor authentication (MFA) on SonicWall Gen6 SSL-VPN appliances to deploy tools used in ransomware attacks.
originalCybersecurity Dive
Patch bypass allows hackers to exploit prior flaw in SonicWall SSL-VPN
Researchers said a wave of attacks began in February targeting firewalls that appeared to be protected.
originalPart of the PlainSec briefing for 2026-05-20
Every edition of this story: Patched SonicWall VPNs Can Still Bypass MFA