CVE-2026-0204 could allow an unauthenticated attacker to access certain management interface functions
CVE-2026-0204 could allow an unauthenticated attacker to access certain management interface functions
The following platforms are known to be affected:
SonicWall has released a security update addressing three vulnerabilities affecting SonicOS. Successful exploitation could allow an unauthenticated attacker to bypass authentication and access certain management interface functions or restricted services.
Affected organisations are encouraged to review SonicWall Security Advisory SNWLID-2026-0004 and apply the relevant updates as soon as possible.
A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions.
A post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted services.
A post-authentication Stack-based Buffer Overflow vulnerabilities in SonicOS allows a remote attacker to crash a firewall.
Last edited: 30 April 2026 1:15 pm
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
