SonicWall Security Advisories & CVEs
3 advisories tracked · SonicWall PSIRT (PSIRT@sonicwall.com CNA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor SonicWall CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Check if your SonicWall device is affected
Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in SonicWall's recent advisories.
Official source
SonicWall PSIRT (PSIRT@sonicwall.com CNA) via NVD
SonicWall is its own CVE Numbering Authority. Its PSIRT portal (psirt.global.sonicwall.com) is a reCAPTCHA-gated JavaScript app with no stable public feed, so VulniPulse ingests SonicWall's CVEs from the NVD CNA feed (PSIRT@sonicwall.com), grouped by the official SNWLID advisory, with affected products and versions from each description and a link back to the SNWLID advisory. Covers SonicOS firewalls (Gen6/Gen7 TZ/NSa/NSsp/NSv), Secure Mobile Access (SMA 100/1000), SSL-VPN, NetExtender, Email Security and GMS/Analytics — SonicWall SSL-VPN is a frequent ransomware entry point.
Latest SonicWall advisories
Medium [CVE-2026-66151] Global VPN Client: SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec…
SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec.sys driver, which could allow a local attacker to cause a system crash.
Medium [CVE-2026-0516] SonicOS: improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipu…
A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header and redirect firewall management users to arbitrary web domains.
Medium [CVE-2026-3468 +2] Email Security: stored Cross-Site Scripting (XSS) vulnerability has been identified in the SonicWall Email Security appliance due to improper…
A stored Cross-Site Scripting (XSS) vulnerability has been identified in the SonicWall Email Security appliance due to improper neutralization of user-supplied input during web page generation, allowing a remote authenticated attacker as admin user to potentially execute arbitrary JavaScript code.