Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4305 articles · 196685 vulns · 37/41 feeds (7d)
← Back to list
6.5
CVE-2026-0516PATCHED
SonicWall · SonicOS

CVE-2026-0516: A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to

Description

A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header and redirect firewall management users to arbitrary web domains.

Affected Products

VendorProductVersions
SonicWallSonicOS6.5.5.2-28n and older versions, 7.0.1-5169 and older versions, 7.3.3-7015 and older versions, 8.2.1-8010 and older versions

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
sonicwallsonicoscert_advisory90%

References

  • https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0009(vendor-advisory)

Related News (3 articles)

Tier B
BSI Advisories18d ago
[NEU] [niedrig] SonicWall SonicOS: Schwachstelle ermöglicht Offenlegung von Informationen
→ No new info (linked only)
Tier B
CERT-FR19d ago
Vulnérabilité dans Sonicwall SonicOS (06 août 2026)
→ No new info (linked only)
Tier C
VulDB19d ago
CVE-2026-0516 | SonicWall SonicOS HTTP Header Processing neutralization
→ No new info (linked only)
CVSS 3.16.5 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0009
CWECWE-644
PublishedAug 5, 2026
Last enriched19d ago
Trending Score6
Source articles3
Independent3
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-15409EXPKEV
CVE-2026-15409: A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
Trending: 40
CRITICALCVE-2026-66147
CVE-2026-66147: An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier
Trending: 15
CRITICALCVE-2026-66145
CVE-2026-66145: An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier version
Trending: 15
HIGHCVE-2026-15410EXP
CVE-2026-15410: Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the S
Trending: 14
HIGHCVE-2026-66149
CVE-2026-66149: Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows
Trending: 12

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 5, 2026
Discovered by ZDM
Aug 5, 2026
Patch Available
Aug 5, 2026