SonicWall SonicOS Vulnerabilities Expose Firewalls to Unauthorized Access and Crashes

SonicWall SonicOS Vulnerabilities Expose Firewalls to Unauthorized Access and Crashes

First seen 30 Apr 2026, 09:25 UTC GbhackersCybersecuritynewsHeise.DeDigital.Nhs.UkSecurityaffairs.Co+4 90% similarity 69.0

Article Content

Browse articles
ThreatCluster

SonicWall has identified three critical vulnerabilities in its SonicOS firewall operating system, disclosed in security advisory SNWLID-2026-0004. The most severe vulnerability, CVE-2026-0204, allows unauthenticated attackers to bypass authentication and access management interface functions, rated with a CVSS score of 8.0. Additionally, CVE-2026-0205 enables logged-in users to exploit a path traversal vulnerability, while CVE-2026-0206 allows for a denial-of-service attack through a stack-based buffer overflow. These vulnerabilities were reported by CrowdStrike and have not yet been actively exploited. SonicWall has released patches for affected firmware versions, urging administrators to apply updates immediately. Organizations using SonicWall firewalls should also consider disabling the management interface temporarily as a precaution. The vulnerabilities could potentially lead to unauthorized access to sensitive functions and service disruptions.

Key Points: • Three vulnerabilities in SonicWall SonicOS allow unauthorized access and denial-of-service attacks. • CVE-2026-0204 has a high severity score of 8.0, enabling unauthenticated access to management functions. • SonicWall has released patches and recommends immediate action to secure affected systems.

ThreatCluster AI

Timeline

2026-04-29
CVE-2026-0204, CVE-2026-0205, CVE-2026-0206 published
2026-04-29
SonicWall security advisory SNWLID-2026-0004 disclosed
2026-04-30
SonicWall releases patches for affected SonicOS versions

Community

Browse all →

Tracked Entities in This Story