What is CVE-2026-0516?
An improper neutralization of HTTP headers for scripting syntax vulnerability was identified in SonicOS. This flaw allows a remote attacker to manipulate the Host header, potentially redirecting firewall management users to arbitrary web domains. SonicOS users should apply official updates immediately.
Azərbaycanca: SonicOS-da HTTP başlıqlarının skript sintaksisi üçün düzgün neytrallaşdırılmaması zəifliyi aşkar edilib. Bu zəiflik uzaqdan hücum edən şəxsə Host başlığını manipulyasiya edərək firewall idarəetmə istifadəçilərini ixtiyari veb domenlərinə yönləndirməyə imkan verir. SonicOS istifadəçiləri rəsmi yeniləmələri tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ1
How does CVE-2026-0516 threaten SonicOS users?
This flaw allows a remote attacker to manipulate the Host header, potentially redirecting firewall management users to arbitrary web domains.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.