logo

SonicWall SonicOS vulnerabilities: How to find impacted assets

ID: 6c2a23d5-d1b6-545d-beb2-af560854d212

STIX ID: report--6c2a23d5-d1b6-545d-beb2-af560854d212

Feed Name: runZero Blog

Threat Score
80/100

Date Published: 2024-09-06

Date Updated: 2026-05-02

Author: Matthew Kienow

...
...

This report aggregates SonicWall security advisories describing multiple high- and critical-severity vulnerabilities across SonicOS (Gen 6/7/8), SMA100, and SMA1000 appliances — including unauthenticated and post-authentication RCE, path traversal, and buffer overflow flaws (notable CVEs: CVE-2026-0204/0205/0206, CVE-2025-40599/40596/40597/40598, CVE-2025-23006, CVE-2024-40766). Vendor guidance urges immediate firmware updates to specified fixed versions, use of MFA/WAF, and provides runZero queries to locate affected assets; one advisory notes evidence of active exploitation for the SMA1000 vulnerability.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.