Vendor advisories

SonicWall PSIRT Advisories

Browse 9 advisories from this official source. Search by product, CVE, severity, or advisory ID.

Current Checked 12 minutes ago Checked hourly

9 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
SonicWall PSIRT AdvisoriesSNWLID-2026-0017
CriticalCVSS 10.0

SonicWall SMA1000 Series Appliances Affected By Multiple Vulnerabilities

1) CVE-2026-102255 - Pre-authentication SSRF via unintended forward-proxy A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker could pote...

Affected productsSMA1000 Models - 6210, 7210, 8200v: 12.4.3-03526 (platform-hotfix) and older versions. 12.5.0-02952 (platform-hotfix) and older versions.
Fixed versionsSMA1000 Models - 6210, 7210, 8200v: 12.4.3-03670 (platform-hotfix) and higher versions. 12.5.0-03082 (platform-hotfix) and higher versions.
Vendor guidance

Install the applicable fixed SonicWall release for your product and branch. SMA1000 Models - 6210, 7210, 8200v: 12.4.3-03670 (platform-hotfix) and higher versions. 12.5.0-03082 (platform-hotfix) and higher versions.

SonicWall PSIRT AdvisoriesSNWLID-2026-0015
CriticalCVSS 9.1

SonicWall NSM On-Prem Affected By Multiple Vulnerabilities

1) CVE-2026-78327 - Authenticated Command Injection Vulnerability An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authenticated at...

Affected productsAffected Product(s): Affected Versions, Network Security Manager (NSM) On-Prem (VMWare, Hyper-V, Azure and KVM): 4.3.0 and earlier versions.
Fixed versionsFixed Product(s): Fixed Versions, Network Security Manager (NSM) On-Prem (VMWare, Hyper-V, Azure and KVM): 4.3.1-R4 and higher versions.
Vendor guidance

Install the applicable fixed SonicWall release for your product and branch. Fixed Product(s): Fixed Versions Network Security Manager (NSM) On-Prem (VMWare, Hyper-V, Azure and KVM): 4.3.1-R4 and higher versions.

SonicWall PSIRT AdvisoriesSNWLID-2026-0016
CriticalCVSS 10.0Priority signal

SonicWall SMA1000 Series Appliances Affected By Multiple Vulnerabilities

1) CVE-2026-83548 - Pre-authentication SSRF via unintended forward-proxy A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vu...

Affected productsSMA1000 Models - 6210, 7210, 8200v: 12.4.3-03453 (platform-hotfix) and older versions. 12.5.0-02835 (platform-hotfix) and older versions.
Fixed versionsSMA1000 Models - 6210, 7210, 8200v: 12.4.3-03526 (platform-hotfix) and higher versions. 12.5.0-02952 (platform-hotfix) and higher versions.
Vendor guidance

Install the applicable fixed SonicWall release for your product and branch. SMA1000 Models - 6210, 7210, 8200v: 12.4.3-03526 (platform-hotfix) and higher versions. 12.5.0-02952 (platform-hotfix) and higher versions.

SonicWall PSIRT AdvisoriesSNWLID-2026-0013
HighCVSS 8.8

SonicWall NetExtender Linux Client Multiple Vulnerabilities

1) CVE-2026-66152 - SonicWall NetExtender arbitrary file write via path traversal vulnerability A Path traversal vulnerability in the SonicWall NetExtender Linux client file extractor component allows an attacker to write arbitrary file as root. CVSS Score: 8.8 CVSS Vector: CV...

Affected productsNetExtender Linux Client: Version 10.3.5 and earlier versions
Fixed versionsNetExtender Linux Client: Version 10.3.6 and higher versions
Vendor guidance

Install the applicable fixed SonicWall release for your product and branch. NetExtender Linux Client: Version 10.3.6 and higher versions

SonicWall PSIRT AdvisoriesSNWLID-2026-0011
CriticalCVSS 9.4

SonicWall GMS Security Affected By Multiple Vulnerabilities

SonicWall GMS (Virtual Appliance, Windows) - 9.5.1 and earlier versions are vulnerable to the following security issues. 1) CVE-2026-66145 - An unauthenticated remote code execution vulnerability An unauthenticated remote code execution vulnerability was identified in GMS 9.5....

Affected productsGMS - Virtual Appliance and Windows: 9.5.1 and earlier versions
Fixed versionsGMS - Virtual Appliance and Windows: 9.5.2
Vendor guidance

Install the applicable fixed SonicWall release for your product and branch. GMS - Virtual Appliance and Windows: 9.5.2

SonicWall PSIRT AdvisoriesSNWLID-2026-0012
HighCVSS 7.8

SonicWall Email Security Affected By Multiple Vulnerabilities

1) CVE-2026-66149 - Improper Control of Generation of Code ('Code Injection') Vulnerability via netmask Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWa...

Affected productsAffected Product(s): Affected Versions, Email Security (ES Appliance 5000, 5050, 7000, 7050, 9000, VMWare and Hyper-V): 10.0.35.8405 and earlier versions.
Fixed versionsFixed Product(s): Fixed Versions, Email Security (ES Appliance 5000, 5050, 7000, 7050, 9000, VMWare and Hyper-V): 10.0.36 and higher versions.
Vendor guidance

Install the applicable fixed SonicWall release for your product and branch. Fixed Product(s): Fixed Versions Email Security (ES Appliance 5000, 5050, 7000, 7050, 9000, VMWare and Hyper-V): 10.0.36 and higher versions.

SonicWall PSIRT AdvisoriesSNWLID-2026-0009
MediumCVSS 4.3

SonicOS Improper Neutralization of HTTP Headers Vulnerability

A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header and redirect firewall management users to arbitrary web domains.

Affected productsAffected Platforms: Affected Versions, Gen6 Hardware Firewalls -SOHOW, SOHO 250, SOHO 250W, TZ 300, TZ 300P, TZ 300W, TZ 350, TZ 350W, TZ 400, TZ 400W, TZ 500, TZ 500W, TZ 600, TZ 600P, NSa 2650, NSa 3600, NSa 3650, NSa 4600, NSa 4650, NSa 5600, NSa 5650, NSa 6600, NSa 6650, SM 9200, SM 9250, SM 9400, SM 9450, SM 9600, SM 9650: 6.5.5.2-28n and older versions, Gen6 NSv - NSv 10, NSv 25, NSv 50, NSv 100, NSv 200, NSv 300, NSv 400, NSv 800, NSv 1600: 6.5.4.4-44v-21-2472 and older versions, Gen7 Hardware Firewalls - TZ 270, TZ 270W, TZ 370, TZ 370W, TZ 470, TZ 470W, TZ 570, TZ 570W, TZ 570P, TZ 670, NSa 2700, NSa 3700, NSa 4700, NSa 5700, NSa 6700, NSsp 10700, NSsp 11700, NSsp 13700, NSsp 15700 Gen7 NSv - NSv 270, NSv 470, NSv 870 (ESX, KVM, HYPER-V, AWS, Azure): 7.0.1-5169 and older versions 7.3.3-7015 and older versions
Fixed versionsFixed Platforms: Fixed Versions, Gen6 Hardware Firewalls - SOHO 250, SOHO 250W, TZ 350, TZ 350W, TZ 500, TZ 500W, NSa 4600, NSa 4650, NSa 5600, NSa 5650, NSa 6600, NSa 6650: Please use the provided workaround, Gen7 Hardware Firewalls - TZ 270, TZ 270W, TZ 370, TZ 370W, TZ 470, TZ 470W, TZ 570, TZ 570W, TZ 570P, TZ 670, NSa 2700, NSa 3700, NSa 4700, NSa 5700, NSa 6700, NSsp 10700, NSsp 11700, NSsp 13700, NSsp 15700 Gen7 NSv - NSv 270, NSv 470, NSv 870 (ESX, KVM, HYPER-V, AWS, Azure): Please use the provided workaround (Fix for GEN7 planned in next release), Gen8 Hardware Firewalls - TZ 80, TZ 280, TZ 280W, TZ 380, TZ 380W, TZ 480, TZ 580, TZ 680, NSa 2800, NSa 3800, NSa 4800, NSa 5800 Gen8 NSv - NSv XS, NSv S, NSv M, NSv L (ESX, KVM, HYPER-V, AWS, Azure): 8.2.2-8015 and higher versions
Vendor guidance

Install the applicable fixed SonicWall release for your product and branch. Fixed Platforms: Fixed Versions Gen6 Hardware Firewalls - SOHO 250, SOHO 250W, TZ 350, TZ 350W, TZ 500, TZ 500W, NSa 4600, NSa 4650, NSa 5600...

SonicWall PSIRT AdvisoriesSNWLID-2026-0010
MediumCVSS 5.5

SonicWall Global VPN Client (GVC) Out-of-bounds kernel memory read vulnerability

SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec.sys driver, which could allow a local attacker to cause a system crash.

Affected productsSonicWall Global VPN Client (GVC): 4.10.8.1108 and earlier versions
Fixed versionsSonicWall Global VPN Client (GVC): 5.0.0.2008 and higher versions
Vendor guidance

Install the applicable fixed SonicWall release for your product and branch. SonicWall Global VPN Client (GVC): 5.0.0.2008 and higher versions

SonicWall PSIRT AdvisoriesSNWLID-2026-0008
CriticalCVSS 10.0Priority signal

SonicWall SMA1000 Series Appliances Affected By Multiple Vulnerabilities

1) CVE-2026-15409 - A Server-side request forgery (SSRF) A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended...

Affected productsSMA1000 Models - 6210, 7210, 8200v: 12.4.3-03245, 12.4.3-03387 and 12.4.3-03434 (platform-hotfix) 12.5.0-02283, 12.5.0-02624 and 12.5.0-02800 (platform-hotfix)
Fixed versionsSMA1000 Models - 6210, 7210, 8200v: 12.4.3-03453 (platform-hotfix) and higher versions. 12.5.0-02835 (platform-hotfix) and higher versions.
Vendor guidance

Install the applicable fixed SonicWall release for your product and branch. SMA1000 Models - 6210, 7210, 8200v: 12.4.3-03453 (platform-hotfix) and higher versions. 12.5.0-02835 (platform-hotfix) and higher versions.

Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.