Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · sonicwall

sonicwall

· 43 Critical

Total CVEs

227

Critical

43

Products

352

Search All CVEs →

227

Products (352)

sonicos68 CVEstz470w37 CVEstz570w37 CVEstz67037 CVEstz37037 CVEstz370w37 CVEstz570p37 CVEstz47037 CVEstz57037 CVEssma 210 firmware35 CVEssma 410 firmware35 CVEstz270w34 CVEssma 41033 CVEssma 500v33 CVEstz27033 CVEssma 21033 CVEsglobal management system32 CVEssma 500v firmware32 CVEsnsa 370027 CVEsnsa 270027 CVEssma 400 firmware27 CVEsnsa 670027 CVEssma 200 firmware27 CVEsnsa 470027 CVEsnssp 1370027 CVEssma 40025 CVEssma 20025 CVEsnsa 265024 CVEsnssp 1170023 CVEsnsa 570023 CVEsnssp 1070023 CVEsnsa 665022 CVEsnsa 465022 CVEsnsa 565022 CVEsnsa 365022 CVEsnssp 1570022 CVEssoho 25020 CVEssoho 250w20 CVEsnsv 27019 CVEssonicosv19 CVEsnsv 87019 CVEsnsv 47019 CVEsanalytics17 CVEsnsa 660016 CVEsnsv47016 CVEsnsv27016 CVEsnsa 560016 CVEsnsa 360016 CVEsnsa 460016 CVEsnsv87016 CVEssohow14 CVEstz 50013 CVEssma 100 firmware13 CVEstz 60013 CVEssm 945013 CVEssm 960013 CVEssm 965013 CVEstz 500w13 CVEstz 600p13 CVEstz 400w13 CVEstz 40013 CVEstz 35013 CVEstz 300w13 CVEstz 300p13 CVEstz 30013 CVEssm 940013 CVEssm 920013 CVEssm 925013 CVEsemail security12 CVEsnsa 260012 CVEsnsv 1011 CVEsnsv 2511 CVEssma 10011 CVEsnsv 40011 CVEsnsv 5011 CVEsnsv 80011 CVEsnsv 10011 CVEsnsv 30011 CVEsnsv 20011 CVEsnsv40010 CVEsnsv30010 CVEsnsv2510 CVEstz600p10 CVEsnsv20010 CVEstz60010 CVEsnsv160010 CVEsanalyzer10 CVEsnsv10010 CVEsnsv 160010 CVEstz300w10 CVEstz300p10 CVEsnsv1010 CVEstz35010 CVEstz350w10 CVEstz40010 CVEstz8010 CVEstz400w10 CVEstz50010 CVEstz500w10 CVEsnsv80010 CVEsnsv5010 CVEsnssp117009 CVEstz6809 CVEstz5809 CVEstz4809 CVEstz3809 CVEsnetextender9 CVEsnsa27009 CVEsnsa37009 CVEsnsa47009 CVEsnsa57009 CVEsnsa67009 CVEstz2809 CVEsnsa 28009 CVEsnsa 38009 CVEsnsa 48009 CVEsnsa 58009 CVEsnsa 92509 CVEsnsa 94509 CVEsnsa 96509 CVEsnssp107009 CVEsnssp137009 CVEsnssp157009 CVEsnssp 124009 CVEsnssp 128009 CVEstz3007 CVEssma1007 CVEsscrutinizer7 CVEssma7200 firmware6 CVEsglobal vpn client6 CVEssma72006 CVEssma6210 firmware6 CVEssma62106 CVEssma8200v6 CVEssma7210 firmware6 CVEssma72106 CVEssma6200 firmware6 CVEssma62006 CVEsemail security appliance 7050 firmware5 CVEsuma em50005 CVEsemail security appliance 70505 CVEssma100 firmware5 CVEsemail security appliance 7000 firmware5 CVEssma1000 firmware5 CVEsemail security appliance 70005 CVEssma10005 CVEsemail security appliance 5050 firmware5 CVEsemail security appliance 9000 firmware5 CVEsemail security appliance 50505 CVEsemail security appliance 5000 firmware5 CVEsemail security appliance 90005 CVEsemail security appliance 50005 CVEssupermassive e104004 CVEsemail security virtual appliance4 CVEshosted email security4 CVEssma 62004 CVEssma 6200 firmware4 CVEssma 62104 CVEssma 6210 firmware4 CVEssma 72004 CVEssma 7200 firmware4 CVEssma 72104 CVEssma 7210 firmware4 CVEssupermassive 92004 CVEssupermassive 94004 CVEssupermassive 96004 CVEssupermassive 98004 CVEssupermassive e102004 CVEssupermassive e108004 CVEstz300p firmware4 CVEstz300w firmware4 CVEstz350 firmware4 CVEstz350w firmware4 CVEstz370 firmware4 CVEstz370w firmware4 CVEstz400 firmware4 CVEstz400w firmware4 CVEstz470 firmware4 CVEstz470w firmware4 CVEstz500 firmware4 CVEstz500w firmware4 CVEstz570 firmware4 CVEstz570p firmware4 CVEstz570w firmware4 CVEstz600 firmware4 CVEstz600p firmware4 CVEstz670 firmware4 CVEstz 350w4 CVEsnssp 12800 firmware3 CVEsssl vpn3 CVEsemail security appliance 83003 CVEsnssp 11700 firmware3 CVEsemail security appliance 4300 firmware3 CVEssoho3 CVEsemail security appliance 43003 CVEsemail security appliance 3300 firmware3 CVEsemail security appliance 33003 CVEscapture client3 CVEsemail security appliance3 CVEsnssp 10700 firmware3 CVEsnsa 9650 firmware3 CVEsnsa 5700 firmware3 CVEsnsa 9450 firmware3 CVEsnsa 5650 firmware3 CVEsnssp 12400 firmware3 CVEsnsv 870 firmware3 CVEsnsv 800 firmware3 CVEsnsv 50 firmware3 CVEsnsv 470 firmware3 CVEsnsv 400 firmware3 CVEsnsv 300 firmware3 CVEsnsv 270 firmware3 CVEsnsv 25 firmware3 CVEsnsv 200 firmware3 CVEsnsv 1600 firmware3 CVEsnsv 10 firmware3 CVEsnsv 100 firmware3 CVEsnssp 15700 firmware3 CVEsnssp 13700 firmware3 CVEsnsa 3650 firmware3 CVEsnsa 2700 firmware3 CVEsnsa 2650 firmware3 CVEstz280w3 CVEsnsa 4700 firmware3 CVEsnsa 4650 firmware3 CVEsnsa 9250 firmware3 CVEsuma em5000 firmware3 CVEsnsa 3700 firmware3 CVEsnsa 6700 firmware3 CVEsesa90003 CVEssma 8000v3 CVEsesa70503 CVEssma 8000v firmware3 CVEsesa70003 CVEsesa50503 CVEstz380w3 CVEsesa50003 CVEsnsa 6650 firmware3 CVEsemail security appliance 8300 firmware3 CVEssws14-242 CVEssra 16002 CVEssws14-24fpoe2 CVEssra 1600 firmware2 CVEssws14-482 CVEssra 42002 CVEssws14-48fpoe2 CVEssra 4200 firmware2 CVEssra 46002 CVEssra 4600 firmware2 CVEssma2102 CVEssoho firewall2 CVEsuma e50002 CVEssoho firmware2 CVEsviewpoint2 CVEssma4002 CVEsnsa 250m2 CVEssma4102 CVEssma500v2 CVEssra 1200 firmware2 CVEsnetwork security manager2 CVEssma2002 CVEssm98002 CVEssws12-10fpoe2 CVEsdirectory services connector2 CVEssws12-82 CVEsuniversal management appliance2 CVEssra 12002 CVEssws12-8poe2 CVEsweb application firewall2 CVEspro3001 CVEspro2001 CVEspro1001 CVEsnssp128001 CVEsnssp124001 CVEse-mail security1 CVEsuma e5000 firmware1 CVEse-class ssl vpn1 CVEs6bk1602-0aa12-0tp0 firmware1 CVEscontent filtering1 CVEscloud global management system1 CVEssma 8200v1 CVEssma 8200v firmware1 CVEssoho21 CVEssoho31 CVEssoho 250 firmware1 CVEssoho 250w firmware1 CVEssonicos enhanced1 CVEssonicos sslvpn nacagent1 CVEssonicwave 224w1 CVEssonicwave 224w firmware1 CVEssonicwave 231c1 CVEssonicwave 231c firmware1 CVEssonicwave 432o1 CVEssonicwave 432o firmware1 CVEssonicwave 6211 CVEssonicwave 621 firmware1 CVEssonicwave 6411 CVEssonicwave 641 firmware1 CVEssonicwave 6811 CVEssonicwave 681 firmware1 CVEssra ex60001 CVEssra ex6000 firmware1 CVEssra ex70001 CVEssra ex7000 firmware1 CVEssra ex90001 CVEssra ex9000 firmware1 CVEssra ex 70001 CVEssra ex 7000 firmware1 CVEssra va1 CVEssra va firmware1 CVEsssl-vpn end-point interrogator\/installer activex control1 CVEsssl vpn2000\/40001 CVEsssl vpn 2001 CVEsaventail sra ex virtual appliance1 CVEsaventail sra ex90001 CVEs6bk1602-0aa12-0tp01 CVEstz 1801 CVEsswitch1 CVEssws12-10fpoe firmware1 CVEssws12-8 firmware1 CVEssws12-8poe firmware1 CVEssws14-24 firmware1 CVEssws14-24fpoe firmware1 CVEssws14-48 firmware1 CVEssws14-48fpoe firmware1 CVEst22701 CVEstele21 CVEstz270 firmware1 CVEstz270w firmware1 CVEstz300 firmware1 CVEsnsa 24001 CVEstz 1901 CVEsaventail sra ex70001 CVEsfirmware1 CVEsaventail sra ex60001 CVEs6bk1602-0aa52-0tp0 firmware1 CVEs6bk1602-0aa52-0tp01 CVEs6bk1602-0aa42-0tp0 firmware1 CVEs6bk1602-0aa42-0tp01 CVEs6bk1602-0aa32-0tp0 firmware1 CVEs6bk1602-0aa32-0tp01 CVEs6bk1602-0aa22-0tp0 firmware1 CVEs6bk1602-0aa22-0tp01 CVEssm102001 CVEssm104001 CVEssm108001 CVEssm92001 CVEssm94001 CVEssm96001 CVEssecure mobile access1 CVEsremote access firmware1 CVEspro 20401 CVEs

Recent Vulnerabilities

View all 227
CVE-2026-0206MEDIUM 4.9

A post-authentication Stack-based Buffer Overflow vulnerabilities in SonicOS allows a remote attacker to crash a firewall.

CVE-2026-0205MEDIUM 6.8

A post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted services.

CVE-2026-0204HIGH 8.0

A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions.

CVE-2026-4116HIGH 7.2

Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user to bypass Workplace/Connect Tunnel TOTP authentication.

CVE-2026-4114MEDIUM 6.6

Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin to bypass AMC TOTP authentication.

CVE-2026-4113HIGH 7.2

An observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances allows a remote attacker to enumerate SSL VPN user credentials.

CVE-2026-4112HIGH 7.2

Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a remote authenticated attacker with read-only administrator privileges to escalate privileges to primary administrator.

CVE-2026-3470LOW 3.8

A vulnerability exists in the SonicWall Email Security appliance due to improper input sanitization that may lead to data corruption, allowing a remote authenticated attacker as admin user could exploit this issue by providing crafted input that corrupts application database.

CVE-2026-3469LOW 2.7

A denial-of-service (DoS) vulnerability exists due to improper input validation in the SonicWall Email Security appliance, allowing a remote authenticated attacker as admin user to cause the application to become unresponsive.

CVE-2026-3468MEDIUM 4.8

A stored Cross-Site Scripting (XSS) vulnerability has been identified in the SonicWall Email Security appliance due to improper neutralization of user-supplied input during web page generation, allowing a remote authenticated attacker as admin user to potentially execute arbitrary JavaScript code.

CVE-2026-3439MEDIUM 4.9

A post-authentication Stack-based Buffer Overflow vulnerability in SonicOS certificate handling allows a remote attacker to crash a firewall.

CVE-2026-0402MEDIUM 4.9

A post-authentication Out-of-bounds Read vulnerability in SonicOS allows a remote attacker to crash a firewall.

CVE-2026-0401MEDIUM 4.9

A post-authentication NULL Pointer Dereference vulnerability in SonicOS allows a remote attacker to crash a firewall.

CVE-2026-0400MEDIUM 4.9

A post-authentication Format String vulnerability in SonicOS allows a remote attacker to crash a firewall.

CVE-2026-0399MEDIUM 4.9

Multiple post-authentication stack-based buffer overflow vulnerabilities in the SonicOS management interface due to improper bounds checking in a API endpoint.

CVE-2025-40602MEDIUM 6.6KEV

A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).

CVE-2025-40605MEDIUM 5.3

A Path Traversal vulnerability has been identified in the Email Security appliance allows an attacker to manipulate file system paths by injecting crafted directory-traversal sequences (such as ../) and may access files and directories outside the intended restricted path.

CVE-2025-40604CRITICAL 9.8

Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signatures, allowing attackers with VMDK or datastore access to modify system files and gain persistent arbitrary code execution.

CVE-2025-40601HIGH 7.5

A Stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted firewall to crash.

CVE-2025-40603MEDIUM 4.5

A potential exposure of sensitive information in log files in SonicWall SMA100 Series appliances may allow a remote, authenticated administrator, under certain conditions to view partial users credential data.

CVE-2025-40600CRITICAL 9.8

Use of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service disruption.

CVE-2025-40598MEDIUM 6.1

A Reflected cross-site scripting (XSS) vulnerability exists in the SMA100 series web interface, allowing a remote unauthenticated attacker to potentially execute arbitrary JavaScript code.

CVE-2025-40597HIGH 7.5

A Heap-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution.

CVE-2025-40596HIGH 7.3

A Stack-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution.

CVE-2025-40599CRITICAL 9.1

An authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface. A remote attacker with administrative privileges can exploit this flaw to upload arbitrary files to the system, potentially leading to remote code execution.