CVE-2026-3468: SonicWall Email Security

Medium severity, CVSS 4.8. EPSS: 0.3% chance of exploitation in the next 30 days.

A stored Cross-Site Scripting (XSS) vulnerability has been identified in the SonicWall Email Security appliance due to improper neutralization of user-supplied input during web page generation, allowing a remote authenticated attacker as admin user to potentially execute arbitrary JavaScript code.

Affected products

  • SonicWall Email Security: before 10.0.35.8405 (fixed in 10.0.35.8405)

Published 2026-03-31. Last modified 2026-07-24.