The SonicWall VPN MFA bypass incident is a very clear reminder that patching is not complete until the required configuration changes are also applied. In this case, attackers brute-forced valid VPN credentials and bypassed MFA on SonicWall Gen6 SSL-VPN appliances because the firmware update for CVE-2024-12802 was installed, but the required LDAP reconfiguration steps were not completed. That is the worst kind of “patched” system: technically updated, operationally still exposed.
The vulnerability is caused by missing MFA enforcement when users authenticate using the UPN login format, allowing attackers with valid credentials to log in without MFA being properly enforced. ReliaQuest observed intrusions where attackers moved from VPN access to internal reconnaissance, credential reuse, RDP access to a domain-joined file server, and attempted deployment of Cobalt Strike and a vulnerable driver likely intended to disable endpoint protection.
Organizations using affected SonicWall Gen6 devices should urgently verify that they have not only installed the latest firmware but also completed the vendor’s manual remediation steps: remove the old LDAP configuration using userPrincipalName, clear cached LDAP users, remove the SSL VPN user domain, reboot, recreate LDAP without userPrincipalName, and take a fresh backup so the vulnerable configuration is not restored later. Gen7 and Gen8 devices are reportedly fully remediated by firmware updates alone, but Gen6 requires this extra operational cleanup.
Security teams should also review VPN logs for suspicious indicators such as sess="CLI", event IDs 238 and 1080, logins from VPS or VPN infrastructure, repeated credential attempts, and successful logins that appear to follow a normal MFA flow. The uncomfortable lesson is that logs may show what looks like MFA success even when the control was bypassed. Because apparently even “successful MFA” now needs verification, since security operations needed one more source of joy.
The bigger lesson is that VPN appliances remain one of the most targeted entry points for ransomware groups and access brokers. Firmware updates, configuration validation, MFA enforcement testing, credential hygiene, EDR monitoring, and migration away from end-of-life appliances must all work together. SonicWall Gen6 SSL-VPN appliances reached end-of-life on April 16, 2026, so organizations still depending on them should plan migration to supported platforms instead of treating legacy VPN access as a permanent life choice.
Threat actors brute-forced VPN credentials and bypassed multi-factor authentication (MFA) on SonicWall Gen6 SSL-VPN appliances to deploy tools used in ransomware attacks. [...]
Source: Hackers bypass SonicWall VPN MFA due to incomplete patching via Bleeping Computer — published 20 May 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.