Product Notice: SonicWall Email Security Affected by Multiple Vulnerabilities

1786446350

Overview

  • CVE-2026-66149: Improper Control of Generation of Code ('Code Injection') Vulnerability via netmask – CVSS Score: 7.8 (High)
  • CVE-2026-66150: Improper Control of Generation of Code ('Code Injection') Vulnerability via SNMP – CVSS Score: 7.8 (High)

There is currently no evidence that any of the vulnerabilities addressed in this release are being exploited in the wild.

This issue affects SonicWall Email Security (ES Appliance 5000, 5050, 7000, 7050, 9000, VMware and Hyper-V) running version 10.0.35.8405 and earlier.

SonicWall strongly advises users of the Email Security products to upgrade to the fixed release version as soon as possible. The latest release is available for download on mysonicwall.com.

Product Impact

Please review the table below to see the products and their versions that are impacted:

Impacted Product(s)

Impacted Version(s)

Email Security (ES Appliance 5000, 5050, 7000, 7050, 9000, VMware and Hyper-V)

10.0.35.8405 and earlier versions

Remediation

Impacted Product(s)

Impacted Version(s)

Fixed Version

Email Security (ES Appliance 5000, 5050, 7000, 7050, 9000, VMware and Hyper-V)

10.0.35.8405 and earlier versions

10.0.36.8557 and higher versions

SonicWall strongly advises all Email Security customers to upgrade to version 10.0.36.8557 or higher as soon as possible via mysonicwall.com.

Related Information

  • Previous Alert
    Product Notice: SMA 1000 Series affected by Multiple Vulnerabilities
    Read More
  • Next Alert
    Product Notice: SonicWall GMS Security Affected By Multiple Vulnerabilities
    Read More