
August 11, 2026
Note: We will continue to monitor for vulnerabilities affecting SonicWall devices and send communications regarding out-of-cycle upgrades when needed. The next regularly scheduled Upkeep tech review for SonicWall devices will be in November 2026.
As part of UpKeep, our feature to keep NWG Manage customers' devices on the latest stable version, we reviewed the latest SonicWall releases and recommend the upgrades detailed below.
Why Are You Sharing This Information?
Even if we're not managing SonicWall devices for you, we want you to have the latest information to help keep your devices secure.
- What should I do if I have a SonicWall device that NWG manages?
If you have a SonicWall device(s) that we manage for you, we already know what hardware you have and what version you need to be on. We’ll handle the upgrade during an upcoming maintenance window (unless you are already running the recommended version). Zendesk notifications will be sent out once maintenance has been scheduled, including details about when implementation will take place. If your devices/locations require different days/times for maintenance to take place, you’ll receive separate tickets. - What if I have a SonicWall device that NWG does not manage?
If you have a SonicWall device(s) in your environment, we suggest you upgrade to the recommended version listed below. - What if I don't have any SonicWall devices?
If you don't have any SonicWall devices, no action is needed.
Which SonicWall Release Do You Recommend?
For Gen7 devices: SonicOS 7.3.2-7010
- SonicOS 7.3.0 brings increased security with better default settings, such as stronger password complexity, login rate limiting and an updated (stable) SSH library.
- It also includes fixes for some known issues in older 7.X firmware.
- The most recent feature release, 7.3.3-7015, is not a General Release and should only be used for features or specific bug fixes if required.
For Gen8 devices: SonicOS 8.2.2-8015
- 8.2.2-8015 includes notable features such as Let’s Encrypt integration and non-reversible password storage. It also resolves a medium-severity host header injection vulnerability (GEN8-14363).
- We only recommend this version for TZ80, TZ280, TZ280P, TZ280W, TZ380, TZ380W, TZ480, TZ580, TZ680, NSa2800, NSa3800, NSa4800, NSa5800 and NSa6800. These devices aren’t compatible with older releases.
NWG does not recommend SonicOS 7.2, 7.1 or 7.0 at this time.
- SonicOS 7.2 is available but not recommended by SonicWall. SonicOS 7.3 resolved known issues still present in 7.2.
- SonicWall support for SonicOS 7.1.X ended on September 30, 2025.
- SonicWall has ended support for all 7.0.X firmware with the exception of SonicOS 7.0.1-5169.
Review Details
SonicOS 8.X
Sonic OS 8.X Review
SonicOS 8.2.0 is the newest firmware branch available. This firmware version was released to support Gen8 hardware. The only hardware currently supported with release 8.2.2-8015 is:
- TZ80, TZ280, TZ280P, TZ280W, TZ380, TZ380W, TZ480, TZ580, TZ680
- NSa2800, NSa3800, NSa4800, NSa5800, NSa6800
SonicOS 8.X Conclusion
SonicOS 8.X should only be used for the Generation 8 hardware (which requires SonicOS 8.X). For Gen8 products, NWG recommends firmware version 8.2.2-8015 as it includes notable features such as Let’s Encrypt integration and non-reversible password storage, along with resolving a medium-severity host header injection vulnerability (GEN8-14363).
SonicOS 7.3
SonicOS 7.3 Review
SonicOS 7.3.0 is the newest firmware that supports the Gen7 line of SonicWall devices. The most recent feature release is 7.3.3-7015. This version is not a General Release and should only be used for features or specific bug fixes if required. Included in the major release are increased security default settings such as stronger password complexity, login rate limiting, and an updated (stable) SSH library. This release also includes some fixes for previous issues in older 7.X firmware. Some notable fixes are:
SonicOS 7.3.2-7010
Issue ID: GEN7-56475
Description: Users authenticated via SAML receive a 60-minute session duration with Google IdP.
Issue ID: GEN7-55784
Description: Syslog is not showing the SSLVPN User login timestamp; only the SSLVPN User logout is mentioned in the report.
Advisory ID: SNWLID-2026-0001
Associated CVEs: CVE-2026-0399, CVE-2026-0400, CVE-2026-0401, CVE-2026-0402, CVE-2026-3439
CVSS v3 Score: 4.9
Description: Multiple post-authentication Stack-based Buffer Overflow vulnerabilities in SonicOS allows a remote attacker to crash a firewall.
SonicOS 7.3.0-7012
Issue ID: GEN7-52710
Description: In a High Availability configuration, a race condition could cause external storage to not be mounted correctly on the secondary device logs and cannot be stored in It.
Issue ID: GEN7-52894
Description: An interface that is part of a custom zone with a name that contains special characters shows the zone and mode as being unassigned.
Issue ID: GEN7-53118
Description: For SAML configuration and downloading the XML metadata from an Identity Provider and then importing this XML file to the firewall will display: Restart
Required!. After clicking the Restart button , only the Identity Provide certificate is saved. The IDP configuration will not be saved.
Issue ID: GEN7-53566 (Vulnerability CVE-2025-40600)
Description: Use of Externally-Controlled Format String vulnerability (PSIRT Advisory: SNWLID-2025-0013) in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service disruption.
SonicOS 7.3 Conclusion
NWG recommends using SonicOS General Release 7.3.2-7010 on all Gen7 devices.
SonicOS 7.2
SonicOS 7.2 Review
SonicOS 7.2 is available but not recommended by SonicWall. The most recent version is 7.2.0-7015 released April of 2005. SonicOS 7.3 resolved some known issues in 7.2. As noted in the 7.3 section, some items which are still an issue in the newest 7.2.0-7015 release are:
Issue ID: GEN7-52894
Description: An interface that is part of a custom zone with a name that contains special characters shows the zone and mode as being unassigned.
Issue ID: GEN7-53118
Description: For SAML configuration and downloading the XML metadata from an Identity Provider and then importing this XML file to the firewall will display: Restart Required!. After clicking the Restart button, only the Identity Provide certificate is saved. The IDP configuration will not be saved.
SonicOS 7.2 Conclusion
NWG does not recommend SonicOS 7.2 at this time.
SonicOS 7.1
SonicOS 7.1 Review
SonicWall support for SonicOS 7.1.X ended on September 30, 2025.
SonicOS 7.1 Conclusion
NWG does not recommend SonicOS 7.1.
SonicOS 7.0
SonicOS 7.0 Review
SonicWall has ended support for all 7.0.X firmware with the exception of SonicOS 7.0.1-5169. SonicWall has stated that SonicOS 7.0.1 firmware should be only used by existing customers who are running SonicOS 7.0.1-5151 or earlier.
SonicOS 7.0 Conclusion
NWG does not recommend SonicOS 7.0.X at this time.
Review Process
- Model Evaluation
- Determines major code revision compatibility
- Vendor Recommended
- https://www.sonicwall.com/support/product-lifecycle-tables/TZ-Series/Firmware
- Newest Version (Mature/GA)
- Evaluate known issues
- Evaluate resolved issues
- Evaluate features as needed
- Evaluate known vulnerabilities
Code Versions Reviewed
- 7.3
- 7.1
- 7.0




