CVE-2024-40766: Patch fixed bug, not config risk
The vulnerability 
What Happened
A critical vulnerability in Sophos Firewall, tracked as CVE-2024-40766, was patched in mid-2024, but attackers continue to exploit organizations who applied the patch without addressing the underlying insecure default configuration. The flaw, which initially enabled remote code execution, was remediated in a firmware update. However, the SANS Internet Storm Center reports that the real threat persists: the patch fixed the code, but the vulnerable configuration - specifically, exposing the firewall’s admin interface and user portal to the WAN - remains unchanged in many deployments.
Why It Matters
This case highlights a recurring blind spot in vulnerability management: patching the software does not fix the architectural risk. Organizations that deployed the firmware update assumed they were secure, but attackers are now bypassing the patched code by leveraging the same exposed services that made CVE-2024-40766 exploitable in the first place. The result is a false sense of security, where patched systems remain compromised due to unchanged network exposure.
Technical Details
CVE-2024-40766 affects Sophos Firewall versions 18.x and earlier, with an CVSS score of 9.8 (Critical). The vulnerability resided in the firewall’s user portal and webadmin interface, allowing unauthenticated attackers to execute remote code. The patch corrected the code-level flaw, but the root cause - these services being accessible from the internet - was not addressed. Attackers are now observed scanning for firewalls that still have the admin interface or user portal exposed to the WAN, even on fully patched versions. Once found, they can pivot to other post-exploitation activities such as credential theft or lateral movement.
Immediate Risk
Organizations running patched Sophos Firewalls with any management interface accessible from the internet remain at high risk. The attack surface is not eliminated by the patch alone; any WAN-exposed admin or user portal is a viable entry point. The most common misconfiguration is leaving the webadmin interface on port 4444 or 8443 open to “Any” on the WAN zone. The risk is amplified because security teams often lack visibility into firewall config drift post-patching.
Security Insight
The Sophos CVE-2024-40766 aftermath mirrors a pattern seen in 2021 with Fortinet’s CVE-2018-13379: a patched SSL VPN flaw that continued to give attackers access because organizations never disabled the vulnerable SSL-VPN portal on their firewalls. The defensive takeaway is that patch management must be coupled with a mandatory “post-patch hardening review” - a discrete step where teams verify that the vulnerable service is no longer exposed to untrusted networks. Without this, a patched CVE is simply a rested attack surface, not a remediated one.
Further Reading
Never miss a security update
Get real-time security alerts delivered to your preferred platform.
Related News
North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign. [...]
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catal
A newly patched security flaw impacting on-premise versions of JetBrains TeamCity has come under active exploitation in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in t