Skip to content
CC-4775

CC-4775

Digital.Nhs.Uk [email protected] (NHS Digital) April 30, 2026

CVE-2026-0204 could allow an unauthenticated attacker to access certain management interface functions

CVE-2026-0204 could allow an unauthenticated attacker to access certain management interface functions

The following platforms are known to be affected:

SonicWall has released a security update addressing three vulnerabilities affecting SonicOS. Successful exploitation could allow an unauthenticated attacker to bypass authentication and access certain management interface functions or restricted services.

Affected organisations are encouraged to review SonicWall Security Advisory SNWLID-2026-0004 and apply the relevant updates as soon as possible.

A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions.

A post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted services.

A post-authentication Stack-based Buffer Overflow vulnerabilities in SonicOS allows a remote attacker to crash a firewall.

Last edited: 30 April 2026 1:15 pm