sonicwall
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting sonicwall.
- CVE-2026-0516A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header and redirect firewall management users to arbitra...6.5
- CVE-2026-15410Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could ...KEV7.2
- CVE-2026-15409A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make...KEV10.0
- CVE-2026-0206A post-authentication Stack-based Buffer Overflow vulnerabilities in SonicOS allows a remote attacker to crash a firewall.4.9
- CVE-2026-0205A post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted services.6.8
- CVE-2026-0204A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions.8.0
- CVE-2026-4116Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user to bypass Workplace/Connect Tunnel TOTP authentication.7.2
- CVE-2026-4114Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin to bypass AMC TOTP authentication.6.6
- CVE-2026-4113An observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances allows a remote attacker to enumerate SSL VPN user credentials.7.2
- CVE-2026-4112Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a remote authenticated attacker with read-only administrator p...7.2
- CVE-2026-3470A vulnerability exists in the SonicWall Email Security appliance due to improper input sanitization that may lead to data corruption, allowing a remote authenticated attacker as admin user could ex...3.8
- CVE-2026-3469A denial-of-service (DoS) vulnerability exists due to improper input validation in the SonicWall Email Security appliance, allowing a remote authenticated attacker as admin user to cause the applic...2.7
- CVE-2026-3468A stored Cross-Site Scripting (XSS) vulnerability has been identified in the SonicWall Email Security appliance due to improper neutralization of user-supplied input during web page generation, all...4.8
- CVE-2026-3439A post-authentication Stack-based Buffer Overflow vulnerability in SonicOS certificate handling allows a remote attacker to crash a firewall.4.9
- CVE-2026-0402A post-authentication Out-of-bounds Read vulnerability in SonicOS allows a remote attacker to crash a firewall.4.9