The broken assumption is that MFA and patch status make SonicWall SSL-VPN safe. Reliaquest says attackers have been brute-forcing accounts in a way that still gets them authenticated access, and the abuse does not trip the usual login alerts. That leaves defenders with a false clean bill of health on appliances that can already be in play.
Reliaquest tied the activity to CVE-2024-12802 and said it has seen the same pattern across multiple incident response cases from February to March 2026. The issue affects SonicWall SSL-VPN appliances, including Gen6 devices that are end-of-life, and SonicWall’s 2025 firmware update does not fully remove the LDAP configuration needed for the bypass on those systems. Gen7 devices are reported to work normally with the patch.
The forward risk is that some organizations have no supported fix path at all on Gen6 hardware, so a patched-and-MFA-enabled posture can still mask active compromise. Attackers get authenticated VPN access, and the normal alerting around failed logins may never fire.