SonicWall Security Updates – 09 April 2026

SonicWall has released security updates to fix several vulnerabilities affecting SonicWall SMA 1000 series appliances, Email Security, and SonicOS.

The addressed vulnerabilities could allow the remote attacker to bypass authentication, gain elevated privileges, perform denial-of-service attacks, conduct cross-site scripting attacks, enumerate SSL VPN user credentials, execute arbitrary code, and gain access to the affected products.

Sample of the addressed vulnerabilities:

1. SonicWall SMA 1000 Privilege Escalation via SQL Injection Vulnerability (CVE- 2026-4112):

  • CVSS: 7.2
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: High
  • User Interaction: None
  • Consequences: Gain Privileges

2. SonicWall SMA 1000 Unicode Possible AMC TOTP Bypass Vulnerability (CVE- 2026-4114):

  • CVSS: 6.6
  • Attack Vector: Network
  • Attack Complexity: High
  • Privileges Required: High
  • User Interaction: None
  • Consequences: Bypass Security
Vulnerabilities
  • CVE-2026-4112
  • CVE-2026-4114
  • CVE-2026-4116
  • CVE-2026-4113
  • CVE-2026-3468
  • CVE-2026-3469
  • CVE-2026-3470
  • CVE-2026-0399
  • CVE-2026-0400
  • CVE-2026-0401
  • CVE-2026-0402
  • CVE-2026-3439
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

SonicWall Security Advisory

References