SonicWall Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with SonicWall products.
Products
- SonicOS68 vulnerabilities
- SMA10026 vulnerabilities
- GMS24 vulnerabilities
- Analytics15 vulnerabilities
- SMA100013 vulnerabilities
- Email Security11 vulnerabilities
- SonicWall SMA10011 vulnerabilities
- NetExtender9 vulnerabilities
- SonicOSv5 vulnerabilities
- SonicWall Email Security5 vulnerabilities
- SonicWall Global VPN Client5 vulnerabilities
- SMA 100 Series4 vulnerabilities
- sma100_firmware4 vulnerabilities
- SonicWall SMA10004 vulnerabilities
- Connect Tunnel3 vulnerabilities
- Global Management System (GMS)3 vulnerabilities
- global_management_system3 vulnerabilities
- SMA1000 Appliances3 vulnerabilities
- sma_200_firmware3 vulnerabilities
- SonicWall SRA/SMA1003 vulnerabilities
- Directory Services Connector2 vulnerabilities
- Email Security Appliance2 vulnerabilities
- SMA100 Appliances2 vulnerabilities
- SonicWall Analytics On-Prem2 vulnerabilities
- SonicWall GMS2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-66150HIGH | Generated title:SonicWall Email Security Restricted CLI OS Command Injection via SNMPImproper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via SNMP. CWE-94Aug 11, 2026 | CVSS7.8v3.1 | EPSS0.199% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-66149HIGH | Generated title:SonicWall Email Security OS Command Injection via Netmask in Restricted CLIImproper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via netmask. CWE-94Aug 11, 2026 | CVSS7.8v3.1 | EPSS0.199% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-18634HIGH | Generated title:SonicWall GMS Insecure Deserialization VulnerabilityAn insecure handling of serialized objects vulnerability was found in the one of the service of GMS application 9.5.1 (Build 9510.1044) and earlier versions. A local attacker with the ability to interact with the service could exploit this behavior to perform unauthorized actions through the affected component. CWE-502Aug 11, 2026 | CVSS8.4v3.1 | EPSS0.221% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-66154HIGH | Generated title:SonicWall GMS Improper Certificate ValidationAn insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1 (Build 9510.1044) and earlier versions which, under a successful MitM attack and controlled network conditions, could permit unauthorized changes. CWE-295Aug 11, 2026 | CVSS8.3v3.1 | EPSS0.13% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-66148MEDIUM | Generated title:SonicWall GMS Command-Line Interface Authenticated Command InjectionAn authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.1044) and earlier versions which allows low-privileged local user to execute system commands with root privileges. CWE-94Aug 11, 2026 | CVSS6.3v3.1 | EPSS1.17% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-66147CRITICAL | Generated title:SonicWall GMS Dispatcher Service Command InjectionAn unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests. CWE-94Aug 11, 2026 | CVSS9.4v3.1 | EPSS1.05% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-66146MEDIUM | Generated title:SonicWall GMS Cross-Site ScriptingMultiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.5.1 (Build 9510.1044) and earlier versions that allow a remote attacker to execute javascript script in a user's browser. CWE-79Aug 11, 2026 | CVSS6.1v3.1 | EPSS0.264% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-66145CRITICAL | Generated title:SonicWall GMS Unauthenticated Remote Code Execution via ZipSlipAn unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip. CWE-94Aug 11, 2026 | CVSS9.1v3.1 | EPSS0.434% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-66151MEDIUM | Generated title:SonicWall Global VPN Client SWIPsec.sys Driver Out-of-Bounds Kernel Memory ReadSonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec.sys driver, which could allow a local attacker to cause a system crash. CWE-125Aug 7, 2026 | CVSS5.5v3.1 | EPSS0.11% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-0516MEDIUM | Generated title:SonicOS HTTP Header Manipulation VulnerabilityA improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header and redirect firewall management users to arbitrary web domains. CWE-644Aug 5, 2026 | CVSS6.5v3.1 | EPSS0.205% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-15410HIGH | SonicWall SMA1000 Appliances Code Injection VulnerabilityPost-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands. CWE-94Jul 14, 2026 | CVSS7.2v3.1 | EPSS76.3% | PoCs3 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2026-15409CRITICAL | SonicWall SMA1000 Appliances Server-Side Request Forgery VulnerabilityA Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location. | CVSS10.0v3.1 | EPSS74.2% | PoCs7 | SignalsListed in CISA KEVKnown ransomware use1 Nuclei template | STIX |
CVE-2026-0206MEDIUM | Generated title:SonicOS Post-Authentication Stack-based Buffer Overflow VulnerabilityA post-authentication Stack-based Buffer Overflow vulnerabilities in SonicOS allows a remote attacker to crash a firewall. CWE-121Apr 29, 2026 | CVSS4.9v3.1 | EPSS0.504% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-0205MEDIUM | Generated title:SonicOS Post-Authentication Path Traversal VulnerabilityA post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted services. CWE-35Apr 29, 2026 | CVSS6.8v3.1 | EPSS0.428% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-0204HIGH | Generated title:SonicOS Access Control Weak Authentication VulnerabilityA vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions. | CVSS8.0v3.1 | EPSS0.417% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-4116HIGH | Generated title:SonicWall SMA1000 Improper Handling of Unicode Encoding Authentication BypassImproper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user to bypass Workplace/Connect Tunnel TOTP authentication. CWE-176Apr 9, 2026 | CVSS7.2v3.1 | EPSS0.417% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-4114MEDIUM | Generated title:SonicWall SMA1000 Improper Handling of Unicode Encoding Authentication BypassImproper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin to bypass AMC TOTP authentication. CWE-176Apr 9, 2026 | CVSS6.6v3.1 | EPSS0.597% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-4113HIGH | Generated title:SonicWall SMA1000 Observable Response Discrepancy Enables SSL VPN User Credential EnumerationAn observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances allows a remote attacker to enumerate SSL VPN user credentials. CWE-204Apr 9, 2026 | CVSS7.2v3.1 | EPSS0.363% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-4112HIGH | Generated title:SonicWall SMA1000 SQL Injection Privilege EscalationImproper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a remote authenticated attacker with read-only administrator privileges to escalate privileges to primary administrator. CWE-89Apr 9, 2026 | CVSS7.2v3.1 | EPSS0.613% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Generated title:SonicWall Email Security Improper Input ValidationA vulnerability exists in the SonicWall Email Security appliance due to improper input sanitization that may lead to data corruption, allowing a remote authenticated attacker as admin user could exploit this issue by providing crafted input that corrupts application database. CWE-20Mar 31, 2026 | CVSS3.8v3.1 | EPSS0.321% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Generated title:SonicWall Email Security Denial of Service via Improper Input ValidationA denial-of-service (DoS) vulnerability exists due to improper input validation in the SonicWall Email Security appliance, allowing a remote authenticated attacker as admin user to cause the application to become unresponsive. CWE-20Mar 31, 2026 | CVSS2.7v3.1 | EPSS0.386% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-3468MEDIUM | Generated title:SonicWall Email Security Stored Cross-Site ScriptingA stored Cross-Site Scripting (XSS) vulnerability has been identified in the SonicWall Email Security appliance due to improper neutralization of user-supplied input during web page generation, allowing a remote authenticated attacker as admin user to potentially execute arbitrary JavaScript code. CWE-79Mar 31, 2026 | CVSS4.8v3.1 | EPSS0.226% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-3439MEDIUM | Generated title:SonicOS Post-Authentication Stack-based Buffer Overflow in Certificate HandlingA post-authentication Stack-based Buffer Overflow vulnerability in SonicOS certificate handling allows a remote attacker to crash a firewall. CWE-121Mar 4, 2026 | CVSS4.9v3.1 | EPSS0.259% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-0402MEDIUM | Generated title:SonicOS Post-Authentication Out-of-Bounds Read VulnerabilityA post-authentication Out-of-bounds Read vulnerability in SonicOS allows a remote attacker to crash a firewall. CWE-125Feb 24, 2026 | CVSS4.9v3.1 | EPSS0.342% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-0401MEDIUM | Generated title:SonicOS Post-Authentication NULL Pointer Dereference Denial of ServiceA post-authentication NULL Pointer Dereference vulnerability in SonicOS allows a remote attacker to crash a firewall. CWE-476Feb 24, 2026 | CVSS4.9v3.1 | EPSS0.342% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |