SonicWallCVE-2026-0516
SonicWall SonicOS: remote attacker could manipulate the Host header
Medium6.5CVE-2026-0516 · Published Aug 5, 2026 · updated Aug 28, 2026
A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header and redirect firewall management users to arbitrary web domains.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| SonicOS Product | <= 6.5.5.2-28n and older versions | No fix yet |
| <= 7.0.1-5169 and older versions | No fix yet | |
| <= 7.3.3-7015 and older versions | No fix yet | |
| <= 8.2.1-8010 and older versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- Severity from
- CISA (its enrichment of the CVE record)
- Weakness
- CWE-644
More SonicWall advisories
All SonicWall| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 11 | SonicWall GMS: improper certificate validation | High8.3 | No fix yet |
| Aug 11 | SonicWall Email Security: code injection | High7.8 | No fix yet |
| Aug 11 | SonicWall GMS: unsafe deserialization | High8.4 | No fix yet |
| Aug 11 | SonicWall GMS: cross-site scripting | Medium6.1 | No fix yet |
| Aug 11 | SonicWall GMS: remote code execution | Critical9.1 | No fix yet |
| Aug 7 | SonicWall Global VPN Client: out-of-bounds read | Medium5.5 | No fix yet |