SonicWall SonicOS Vulnerabilities Allow Attackers to Bypass Access Controls and Crash Firewall
ID: afee268d-5936-5a33-be18-9b0c44df05ab
STIX ID: report--afee268d-5936-5a33-be18-9b0c44df05ab
Feed Name: cybersecurityNews.com
SonicWall released an advisory for three SonicOS vulnerabilities (CVE-2026-0204 — improper access control, CVE-2026-0205 — post-auth path traversal, CVE-2026-0206 — post-auth stack buffer overflow) affecting Generation 6–8 hardware and virtual firewalls. Administrators are urged to apply provided firmware updates (Gen6: 6.5.5.2-28n; Gen7: 7.3.2-7010; Gen8: 8.2.0-8009) or implement temporary mitigations (disable HTTP/HTTPS management and SSLVPN, restrict management to SSH); a specific warning notes Gen6 firmware downgrades will delete LDAP users and reset MFA, so backups and caution are required.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
