logo

SonicWall SonicOS Vulnerabilities Allow Attackers to Bypass Access Controls and Crash Firewall

ID: afee268d-5936-5a33-be18-9b0c44df05ab

STIX ID: report--afee268d-5936-5a33-be18-9b0c44df05ab

Feed Name: cybersecurityNews.com

Threat Score
60/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Abinaya

...
...

SonicWall released an advisory for three SonicOS vulnerabilities (CVE-2026-0204 — improper access control, CVE-2026-0205 — post-auth path traversal, CVE-2026-0206 — post-auth stack buffer overflow) affecting Generation 6–8 hardware and virtual firewalls. Administrators are urged to apply provided firmware updates (Gen6: 6.5.5.2-28n; Gen7: 7.3.2-7010; Gen8: 8.2.0-8009) or implement temporary mitigations (disable HTTP/HTTPS management and SSLVPN, restrict management to SSH); a specific warning notes Gen6 firmware downgrades will delete LDAP users and reset MFA, so backups and caution are required.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.