
- SonicWall patches SSLVPN flaw CVE-2025-40601, enabling unauthenticated DoS attacks on Gen7/Gen8 firewalls
- No exploitation seen yet; users urged to disable SSLVPN or restrict access if updates delayed
- Two Email Security appliance flaws (CVE-2025-40604/40605) also fixed, preventing code execution and data access
SonicWall has released a patch for a high-severity vulnerability in its SonicOS SSLVPN service, and urged all users to update their firewalls immediately.