SonicWall has released security advisories addressing multiple vulnerabilities affecting its Email Security appliances and Gen7/Gen8 hardware and virtual firewalls. The most critical issue is a stack-based buffer overflow vulnerability in the SonicOS SSLVPN service, tracked as CVE-2025-40601, which allows remote unauthenticated attackers to cause a denial-of-service condition and crash impacted firewalls. SonicWall has stated that there is no evidence of active exploitation or public proof-of-concept code for this vulnerability, but urges immediate patching. The affected products include various models of Gen7 and Gen8 firewalls, with fixed versions now available. Gen6 firewalls and SMA SSL VPN products are not affected.
In addition to the firewall vulnerability, SonicWall also patched two vulnerabilities in its Email Security appliances, which could enable remote attackers to compromise these systems. Administrators unable to immediately apply the updates are advised to disable the SSLVPN service or restrict access to trusted sources as a temporary mitigation. The Canadian Centre for Cyber Security and SonicWall both recommend that users and administrators review the advisories and apply the necessary updates to protect their environments from potential exploitation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
SonicWall also released patches for two Email Security flaws: CVE-2025-40604, which could enable persistent arbitrary code execution, and CVE-2025-40605, which could allow access to restricted information. These fixes were disclosed separately in connection with the same advisory coverage.
Alongside the advisory, SonicWall recommended that customers who could not immediately update disable the SonicOS SSLVPN service or restrict access to trusted sources to reduce exposure to denial-of-service attacks. These mitigations were presented as interim protections until patches could be applied.
SonicWall issued a security advisory for CVE-2025-40601, a high-severity stack-based buffer overflow in SonicOS SSLVPN that can be exploited remotely without authentication to crash affected firewalls. The company released fixed versions for affected Gen7 and Gen8 hardware and virtual firewall platforms and said it was not aware of active exploitation or a public proof-of-concept.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.