CVE-2026-0204Patch(sonicwall / nsa_2650)

MEDIUMCVSS 8.0 · HIGH

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch sonicwall nsa_2650 systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions.

4.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306CWE-1390

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nsa_2650
  • nsa_2700
  • nsa_2800
  • nsa_3600

Threat summary

  • Active exploitation appears in 3 classified signals
  • Patch or workaround signal is available
  • 17 mentions across 9 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 3 signals
  • Patch or workaround mentioned in 10 signals
  • Technical details provided in 11 signals
  • Disclosure: 5 classified signals
  • Peaked 7d ago at 5 mentions (2026-04-30); latest day: 1
  • 17 total mentions across 9 days

Affected systems

Vendors
Products
nsa_2650nsa_2700nsa_2800nsa_3600nsa_3650nsa_3700nsa_3800nsa_4600nsa_4650nsa_4700

1 version affected across 64 products

Deep dive

Activity timeline17 mentions / 9d
01345Mentions · 2026-04-29: 3Mentions · 2026-04-30: 5Mentions · 2026-05-01: 3Mentions · 2026-05-02: 1Mentions · 2026-05-04: 1Mentions · 2026-05-06: 1Mentions · 2026-05-07: 1Mentions · 2026-05-22: 1Mentions · 2026-08-05: 1Active Exploitation · 2026-05-01: 2Active Exploitation · 2026-08-05: 1Patch / Workaround · 2026-04-30: 4Patch / Workaround · 2026-05-01: 2Patch / Workaround · 2026-05-02: 1Patch / Workaround · 2026-05-04: 1Patch / Workaround · 2026-05-07: 1Patch / Workaround · 2026-05-22: 1Technical Details · 2026-04-29: 3Technical Details · 2026-04-30: 3Technical Details · 2026-05-01: 1Technical Details · 2026-05-02: 1Technical Details · 2026-05-04: 1Technical Details · 2026-05-07: 1Technical Details · 2026-05-22: 104-2904-3005-0105-0205-0405-0605-0705-2208-05
Signal classification4 categories
Patch
952.9%
Disclosure
529.4%
Active Exploitation
211.8%
General
15.9%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-04-293
Disclosure3
2026-04-305
Disclosure1Patch4
2026-05-013
Active Exploitation1General1Patch1
2026-05-021
Patch1
2026-05-041
Patch1
2026-05-061
Disclosure1
2026-05-071
Patch1
2026-05-221
Patch1
2026-08-051
Active Exploitation1
Full discourse17 posts
  • Netlas.io@Netlas_io
    General

    CVE-2026-0204 and other: Several vulnerabilities in SonicWall SonicOS, up to 8.0 rating 🔥 Several vulnerabilities in SonicWall SonicOS allow attacker to bypass access controls, to interact with usually restricted services, or to crash a firewall. 👉 https://nt.ls/H8DoW

    Post summary

    The post highlights that several SonicWall SonicOS vulnerabilities (including CVE-2026-0204) can bypass access controls, access restricted services, or crash a firewall, but it provides no details on PoC, active exploitation, patch, or debunking.

    01032355
    7.6K followersView on X
  • にゃん☆たく/takumi.a@taku888infinity
    Disclosure

    【セキュリティ ニュース】「SonicOS」に複数の脆弱性 - 認証回避やDoSのおそれ(1ページ目 / 全2ページ):Security NEXT https://www.security-next.com/183971 『「CVE-2026-0204」は、アクセス制御の不備に起因する脆弱性。認証処理に問題があり、特定の条件下で管理インタフェースにアクセスが可能となる。』

    Post summary

    The announcement reports a CVE involving authentication bypass in SonicOS, with basic technical details but no PoC, exploit, patch, or evidence of active exploitation.

    000311.1K
    11.7K followersView on X
  • Lupovis@LupovisDefence
    Active Exploitation

    There's been an increase in IPs targeting SonicWall CVEs   Sonicwall edge appliances are getting scanned harder every month.   The first 2 days of August are already the most intense we have logged: 8.5 unique
attacker IPs per active day, vs 3.5 in July.   The critical CVE CVE-2026-0204 for SonicOS was recorded at the end of April with scanning activity seen in May.
The two critical CVEs for SonicWall's SMA1000 CVE-2026-15409/10 were recorded in July and we're seeing these being intensely scanned.   Here is the 12-month trend from our decoy fleet.   It is clear SonicWall is becoming increasingly attractive to attackers as seen by the recent ransomware campaign targeting these devices.   Are you running SonicWall edge appliances? Get in touch to see how Lupovis can keep you up to date on the trends affecting your infrastructure.   #ThreatIntelligence #CyberSecurity #SonicWall #KEV #AttackSurface #DeceptionTechnology #CVE

    Post summary

    The post reports increased scanning and active exploitation of SonicWall CVEs, including a ransomware campaign, but offers no PoC, exploit tools, patches, or detailed vulnerability data.

    10000120
    576 followersView on X
  • iototsecnews@iototsecnews
    Patch

    SonicOS の脆弱性 CVE-2026-0204/0205/0206 が FIX:アクセス制御回避と DoS の恐れ https://iototsecnews.jp/2026/04/30/sonicwall-sonicos-vulnerabilities-allow-attackers-to-bypass-access-controls-and-crash-firewall/ SonicWall の脆弱性 CVE-2026-0204/0205/0206 は、ソフトウェアの設計段階での不備が主な原因となっています。具体的には、アクセス制御や認証機能が不十分であったり、プログラムが扱うデータ経路やメモリ管理の問題が発生しています。CVE-2026-0204 のような認証のバグにより、本来は触れられない管理画面が操作されるリスクが生じます。また、プログラムが想定外の動きをするパス・トラバーサルやバッファ・オーバーフローといった現象も重大な侵害の要因になります。ご利用のチームは、ご注意ください。 #CVE20260204 #CVE20260205 #CVE20260206 #SonicOS #SonicWall #Vulnerability

    Post summary

    The post reports that SonicWall’s CVE‑2026‑0204/0205/0206 have been fixed, outlining key access‑control and memory‑management flaws but providing no evidence of PoC or active exploitation.

    01000128
    487 followersView on X
  • Techgines@nxtgen579255
    Patch

    🚨 FIREWALL ALERT: SonicWall just patched CVE-2026-0204 — a CVSS 8.0 authentication bypass in SonicOS that hits Gen6, Gen7, AND Gen8 firewalls simultaneously. No credentials needed. Unauthenticated adjacent-network attacker can reach management. 🔗 http://techgines.com/post/cve-2026-0204-sonicwall-sonicos-authentication-bypass-firewall https://t.co/isoepeN6ku

    Post summary

    SonicWall has released a patch for CVE‑2026‑0204, an authentication bypass with CVSS 8.0, and the announcement provides details and a link to the patch release.

    0001053
    5 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    SonicWall released patches for three SonicOS vulnerabilities across Gen 6, 7, and 8 firewalls, including a high-severity access control bypass (CVE-2026-0204). SSH access restrictions recommended until updates applied. #FirewallSecurity #VulnerabilityPatch https://ift.tt/2pSvziY

    Post summary

    SonicWall announced patches for three SonicOS vulnerabilities, including the high‑severity access control bypass CVE-2026‑0204, and recommends restricting SSH until updates are applied. The post focuses on mitigation steps rather than exploitation details.

    00010116
    4.1K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    1) CVE-2026-0204 - SonicOS Improper Access Control Vulnerability 2) CVE-2026-0205 - SonicOS post-authentication Path Traversal vulnerability 3) CVE-2026-0206 - SonicOS post-authentication Stack-based Buffer Overflow vulnerability https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0004

    Post summary

    The text announces three new SonicOS CVEs with brief technical descriptors, but contains no PoC, exploit code, active exploitation, or patch information.

    00010393
    6.8K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: #SonicWall patched 3 vulnerabilities in #SonicOS (CVE-2026-0204, CVSS 8.1; CVE-2026-0205, CVSS 6.8; CVE-2026-0206, CVSS 4.9). The vulnerabilities can lead to unauthorized access and firewall disruption. Time to #Patch #Patch #Patch

    Post summary

    SonicWall has released patches for CVE‑2026‑0204, CVE‑2026‑0205, and CVE‑2026‑0206, and users are urged to apply them promptly.

    01000242
    7.2K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    SonicWall discloses critical SonicOS flaws (CVE-2026-0204) hitting Gen6 to Gen8 hardware. Apply the 2026 firmware patch now to prevent unauthorized access. #SonicWall #CyberSecurity #FirewallSecurity #InfoSec #PatchNow #NetworkSecurity #SonicOS https://securityonline.info/sonicwall-sonicos-critical-vulnerabilities-gen6-gen7-gen8-patch/ https://t.co/0hzJRPmpXf

    Post summary

    SonicWall publicizes critical flaws in SonicOS (CVE‑2026‑0204) and urges immediate firmware patching to prevent unauthorized access.

    00001344
    11.5K followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH SEVERITY: CVE-2026-0204 (CVSS 8.0) affects SonicOS access control. Vulnerability allows unauthorized access to management interface functions under specific conditions. SonicWall users: patch immediately. #CVE #PatchNow https://t.co/HTBl97fpbc

    Post summary

    A high‑severity vulnerability (CVSS 8.0) in SonicOS allows unauthorized access to the management interface, and SonicWall users are urged to apply the patch immediately.

    0000053
    30 followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidad en productos SonicWall ❗ CVE-2026-0204 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-sonicwall-3/ https://t.co/UywEHJbX8o

    Post summary

    The tweet announces a SonicWall vulnerability (CVE-2026-0204) and points to external sources for details, but offers no technical, exploit, or mitigation information.

    00000120
    6.7K followersView on X
  • ねこさん⚡(ΦωΦ)@catnap707
    Patch

    SonicWall patches three SonicOS flaws in Gen 6, 7 and 8 firewalls. Patch them now https://securityaffairs.com/191527/security/sonicwall-patches-three-sonicos-flaws-in-gen-6-7-and-8-firewalls-patch-them-now.html "The most severe vulnerability, tracked as CVE-2026-0204 (CVSS score of 8.0), is an improper access control issue in SonicOS."

    Post summary

    The article announces a patch for three SonicOS flaws, highlighting CVE-2026-0204 as an improper access control issue with a CVSS score of 8.0, and urges immediate application of the patch.

    00000163
    3.5K followersView on X
  • Vladimir Cageyv Samoylov@cageyvdev
    Patch

    🚨 Security Alert: Patch SonicWall firewalls (CVE-2026-0204/5/6) & Linux 'CopyFail' (CVE-2026-31431) NOW – root exploits live! AI Commerce: Amazon's podcast-style product summaries & Snapchat's conversational ads rolling out. Execs: Patch first! #CyberSec #AI

    Post summary

    The alert warns that CVE-2026-0204/5/6 in SonicWall firewalls and CVE-2026-31431 (Linux "CopyFail") are being exploited for root privileges, urging immediate patching.

    0000095
    27 followersView on X
  • Machina Record@MachinaRecord
    Active Exploitation

    🚨cPanelの重大な脆弱性、2月下旬からゼロデイ攻撃で悪用される(CVE-2026-41940) ⚠️SonicWall、ファイアウォール脆弱性への速やかなパッチ適用を呼びかけ(CVE-2026-0204、CVE-2026-0205他) 〜サイバーアラート5月1日〜 https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/45438/

    Post summary

    The post reports that cPanel CVE-2026-41940 is being actively exploited as a zero‑day since late February, and urges immediate patching for SonicWall firewall vulnerabilities (CVE-2026-0204, CVE-2026-0205).

    00000272
    1.3K followersView on X
  • breachcache@breachcache
    Patch

    Patch your SonicWalls ASAP and don’t publicly expose your management console! CVE-2026-0204 CVE-2026-0205 CVE-2026-0206 https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0004

    Post summary

    The post urges SonicWall users to urgently patch for CVE‑2026‑0204/0205/0206 and warns against exposing the management console, though it offers no technical exploit details or patch specifics.

    0000073
    24 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-0204 Access Control Vulnerability in SonicOS Management Interface Functions https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-0204 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The text announces the existence of CVE‑2026‑0204, an access‑control flaw in SonicOS, and directs users to a vulnerability detail page and a notification link.

    0000057
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-0204 A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions. https://www.cve.org/CVERecord?id=CVE-2026-0204

    Post summary

    The entry announces CVE-2026-0204, describing an access control flaw in SonicOS that may expose management functions under certain conditions, without providing PoC, exploit details, patches, or evidence of active usage.

    00000111
    57.3K followersView on X
CPE platform detail64 entries

64 of 64 entries

PartVendorProductVersionTarget SWTarget HW
HWsonicwallnsa_2650---
HWsonicwallnsa_2700---
HWsonicwallnsa_2800---
HWsonicwallnsa_3600---
HWsonicwallnsa_3650---
HWsonicwallnsa_3700---
HWsonicwallnsa_3800---
HWsonicwallnsa_4600---
HWsonicwallnsa_4650---
HWsonicwallnsa_4700---
HWsonicwallnsa_4800---
HWsonicwallnsa_5600---
HWsonicwallnsa_5650---
HWsonicwallnsa_5700---
HWsonicwallnsa_5800---
HWsonicwallnsa_6600---
HWsonicwallnsa_6650---
HWsonicwallnsa_6700---
HWsonicwallnssp_10700---
HWsonicwallnssp_11700---
HWsonicwallnssp_13700---
HWsonicwallnssp_15700---
HWsonicwallnsv_270---
HWsonicwallnsv_470---
HWsonicwallnsv_870---
HWsonicwallsm_9200---
HWsonicwallsm_9250---
HWsonicwallsm_9400---
HWsonicwallsm_9450---
HWsonicwallsm_9600---
HWsonicwallsm_9650---
HWsonicwallsoho_250---
HWsonicwallsoho_250w---
HWsonicwallsohow---
OSsonicwallsonicos---
HWsonicwalltz270---
HWsonicwalltz270w---
HWsonicwalltz280---
HWsonicwalltz280w---
HWsonicwalltz370---
HWsonicwalltz370w---
HWsonicwalltz380---
HWsonicwalltz380w---
HWsonicwalltz470---
HWsonicwalltz470w---
HWsonicwalltz480---
HWsonicwalltz570---
HWsonicwalltz570p---
HWsonicwalltz570w---
HWsonicwalltz580---
HWsonicwalltz670---
HWsonicwalltz680---
HWsonicwalltz80---
HWsonicwalltz_300---
HWsonicwalltz_300p---
HWsonicwalltz_300w---
HWsonicwalltz_350---
HWsonicwalltz_350w---
HWsonicwalltz_400---
HWsonicwalltz_400w---
HWsonicwalltz_500---
HWsonicwalltz_500w---
HWsonicwalltz_600---
HWsonicwalltz_600p---

Explore more