SonicWall Security Updates – 30 April 2026

SonicWall has released security updates to fix several vulnerabilities affecting multiple SonicWall products.

The addressed vulnerabilities could allow the attacker to crash a firewall, gain elevated privileges, and gain access to the affected systems.

Sample of the addressed vulnerabilities:

1. SonicOS Improper Access Control Vulnerability (CVE-2026-0204):

  • CVSS: 8.0
  • Attack Vector: Adjacent Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Gain Access

2. SonicOS Post-Authentication Path Traversal Vulnerability (CVE-2026-0205):

  • CVSS: 6.8
  • Attack Vector: Adjacent Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Gain Privileges

The affected products:

  • Gen6 Hardware Firewalls.
  • Gen7 NSv.
  • Gen7 Firewalls.
  • Gen8 Firewalls.
Vulnerabilities
  • CVE-2026-0204
  • CVE-2026-0205
  • CVE-2026-0206
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

SonicWall Security Advisory

References