CVE Tools

Sonicos

83 CVEs tracked. 3 of them are in CISA KEV.

This hub aggregates every CVE we track for Sonicos, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.

Sonicos CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Sonicos CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-019
2025-020
2025-030
2025-041
2025-050
2025-060
2025-071
2025-080
2025-090
2025-100
2025-111
2025-120
2026-010
2026-024
2026-031
2026-043
2026-050
2026-060
2026-070
2026-081
2026-090

Severity

How the 83 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical1518%
  • High3340%
  • Medium3542%

Latest CVEs

The 15 most recently published vulnerabilities affecting Sonicos.

  1. CVE-2026-0516A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header and redirect firewall management users to arbitra...6.5
  2. CVE-2026-0206A post-authentication Stack-based Buffer Overflow vulnerabilities in SonicOS allows a remote attacker to crash a firewall.4.9
  3. CVE-2026-0205A post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted services.6.8
  4. CVE-2026-0204A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions.8.0
  5. CVE-2026-3439A post-authentication Stack-based Buffer Overflow vulnerability in SonicOS certificate handling allows a remote attacker to crash a firewall.4.9
  6. CVE-2026-0402A post-authentication Out-of-bounds Read vulnerability in SonicOS allows a remote attacker to crash a firewall.4.9
  7. CVE-2026-0401A post-authentication NULL Pointer Dereference vulnerability in SonicOS allows a remote attacker to crash a firewall.4.9
  8. CVE-2026-0400A post-authentication Format String vulnerability in SonicOS allows a remote attacker to crash a firewall.4.9
  9. CVE-2026-0399Multiple post-authentication stack-based buffer overflow vulnerabilities in the SonicOS management interface due to improper bounds checking in a API endpoint.4.9
  10. CVE-2025-40601A Stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted firewall to crash.7.5
  11. CVE-2025-40600Use of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service disruption.9.8
  12. CVE-2025-32818A Null Pointer Dereference vulnerability in the SonicOS SSLVPN Virtual office interface allows a remote, unauthenticated attacker to crash the firewall, potentially leading to a Denial-of-Service (...7.5
  13. CVE-2024-12802SSL-VPN MFA Bypass in SonicWALL SSL-VPN can arise in specific cases due to the separate handling of UPN (User Principal Name) and SAM (Security Account Manager) account names when integrated with M...9.1
  14. CVE-2024-12806A post-authentication absolute path traversal vulnerability in SonicOS management allows a remote attacker to read an arbitrary file.4.9
  15. CVE-2024-12805A post-authentication format string vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution.7.2

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store