CVE-2026-3468: SonicWall Email Security
Medium severity, CVSS 4.8. EPSS: 0.3% chance of exploitation in the next 30 days.
A stored Cross-Site Scripting (XSS) vulnerability has been identified in the SonicWall Email Security appliance due to improper neutralization of user-supplied input during web page generation, allowing a remote authenticated attacker as admin user to potentially execute arbitrary JavaScript code.
Affected products
- SonicWall Email Security: before 10.0.35.8405 (fixed in 10.0.35.8405)
Published 2026-03-31. Last modified 2026-07-24.