Skip to content
SonicWallCVE-2026-0516

SonicWall SonicOS: remote attacker could manipulate the Host header

Medium6.5CVE-2026-0516 · Published Aug 5, 2026 · updated Aug 28, 2026

A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header and redirect firewall management users to arbitrary web domains.

SonicWall advisory

Affected versions

PackageAffectedFixed in
SonicOS
Product
<= 6.5.5.2-28n and older versionsNo fix yet
<= 7.0.1-5169 and older versionsNo fix yet
<= 7.3.3-7015 and older versionsNo fix yet
<= 8.2.1-8010 and older versionsNo fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Severity from
CISA (its enrichment of the CVE record)
Weakness
CWE-644

More SonicWall advisories

All SonicWall
Advisory
SonicWall GMS: improper certificate validation
High8.3Aug 11
SonicWall Email Security: code injection
High7.8Aug 11
SonicWall GMS: unsafe deserialization
High8.4Aug 11
SonicWall GMS: cross-site scripting
Medium6.1Aug 11
SonicWall GMS: remote code execution
Critical9.1Aug 11
SonicWall Global VPN Client: out-of-bounds read
Medium5.5Aug 7

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.