Back to vendor advisories
SonicWall PSIRT AdvisoriesSNWLID-2026-0012

SonicWall Email Security Affected By Multiple Vulnerabilities

1) CVE-2026-66149 - Improper Control of Generation of Code ('Code Injection') Vulnerability via netmask Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via netmask. CVSS Score: 7.8 CVSS Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CWE-94: Improper Control of Generation of Code ('Code Injection') 2) CVE-2026-66150 - Improper Control of Generation of Code ('Code Injection') Vulnerability via SNMP Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via SNMP. CVSS Score: 7.8 CVSS Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CWE-94: Improper Control of Generation of Code ('Code Injection') SonicWall strongly advises users of the Email Security products (ES Appliance 5000, 5050, 7000, 7050, 9000, VMWare and Hyper-V) to upgrade to the mentioned fixed release version to address these vulnerabilities. There is currently no evidence any of the vulnerabilities addressed in this release are being exploited in the wild.

7.8CVSS out of 10High severity
Scope

What the vendor says is affected

  • Affected Product(s): Affected Versions
  • Email Security (ES Appliance 5000, 5050, 7000, 7050, 9000, VMWare and Hyper-V): 10.0.35.8405 and earlier versions.

Versions the vendor lists as fixed

  • Fixed Product(s): Fixed Versions
  • Email Security (ES Appliance 5000, 5050, 7000, 7050, 9000, VMWare and Hyper-V): 10.0.36 and higher versions.
Next step

What the vendor recommends

Install the applicable fixed SonicWall release for your product and branch. Fixed Product(s): Fixed Versions Email Security (ES Appliance 5000, 5050, 7000, 7050, 9000, VMWare and Hyper-V): 10.0.36 and higher versions.

Review the complete instructions on the vendor's site
Timeline

When this advisory changed

  1. Published by SonicWall

    The publication date reported by the vendor.

  2. Added to SecurityAlert

    We collected the advisory from the official source.

Vulnerabilities

CVEs named in this advisory