CVE-2026-3468: XSS
A stored Cross-Site Scripting (XSS) vulnerability has been identified in the SonicWall Email Security appliance due to improper neutralization of user-supplied input during web page generation, allowing a remote authenticated attacker as admin user to potentially execute arbitrary JavaScript code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3468?
CVE-2026-3468 is considered a high-severity vulnerability due to its potential to allow remote attackers to execute arbitrary JavaScript code.
How do I fix CVE-2026-3468?
To fix CVE-2026-3468, update your SonicWall Email Security appliance to the latest patched version as provided by SonicWall.
Who can exploit CVE-2026-3468?
CVE-2026-3468 can be exploited by authenticated attackers who have admin access to the SonicWall Email Security appliance.
What type of vulnerability is CVE-2026-3468?
CVE-2026-3468 is a stored Cross-Site Scripting (XSS) vulnerability affecting the SonicWall Email Security appliance.
Is CVE-2026-3468 under active exploitation?
As of now, there is no public information indicating that CVE-2026-3468 is being actively exploited in the wild.