SonicWall disclosed multiple vulnerabilities in SonicOS affecting Generation 6, 7, and 8 hardware and virtual firewall products, including flaws that could let attackers bypass access controls, reach restricted services, or trigger denial of service by crashing firewalls. The issues, identified by CrowdStrike’s Advanced Research Team and tracked as CVE-2026-0204, CVE-2026-0205, and CVE-2026-0206, carry CVSS scores of 8.0, 6.8, and 4.9 respectively, and were also reflected in advisory dCERT 2026-1294.
SonicWall released fixed firmware versions and urged administrators to apply updates immediately. Where patching cannot be completed at once, the company advised disabling HTTP/HTTPS management and SSLVPN on all interfaces and restricting management access to SSH. SonicWall also warned Generation 6 customers not to downgrade from patched firmware, saying a rollback will delete LDAP users and reset MFA configurations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
SonicWall said three SonicOS vulnerabilities were discovered by CrowdStrike's Advanced Research Team. The flaws were tracked as CVE-2026-0204, CVE-2026-0205, and CVE-2026-0206.
On 2026-04-30, SonicWall disclosed multiple SonicOS vulnerabilities affecting Generation 6, 7, and 8 hardware and virtual firewall products. The company released fixed firmware versions and recommended mitigations including disabling HTTP/HTTPS management and SSLVPN where immediate patching was not possible.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.