SonicWall Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for SonicWall products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
21
In CISA KEV
17
Beyond CISA KEV
4
Sensor Observed
2
Virtual Patch Available
1
SonicWall KEVs Added by Year
21 SonicWall KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2026-15410
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management... |
SMA1000 | Confirmed | In CISA | 14 Jul 2026 |
|
CVE-2026-15409
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated... |
SMA1000 | Confirmed | In CISA | 14 Jul 2026 |
|
CVE-2023-34133
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SonicWall GMS and Analytics allows an... |
GMS, Analytics | High | Not in CISA | 07 Jul 2025 |
|
CVE-2025-40602
A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC). |
SMA1000 | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2023-44221
Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative... |
SMA100 | Confirmed | In CISA | 01 May 2025 |
|
CVE-2018-9866
A vulnerability in lack of validation of user-supplied parameters pass to XML-RPC calls on SonicWall Global Management System (GMS) virtual... |
Global Management System (GMS) | High | Not in CISA | 26 Apr 2025 |
|
CVE-2022-22274
A Stack-based buffer overflow vulnerability in the SonicOS via HTTP request allows a remote unauthenticated attacker to cause Denial of Service... |
SonicOS | High | Not in CISA | 28 Apr 2025 |
|
CVE-2023-0656
A Stack-based buffer overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could... |
SonicOS | High | Not in CISA | 28 Apr 2025 |
|
CVE-2021-20016
A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access... |
SonicWall SMA100 | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-20023
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the... |
Email Security | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-20022
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the... |
Email Security | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2019-7481
Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity impacted SMA100... |
SMA100 | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-20021
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP... |
Email Security | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-20038
A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated... |
SonicWall SMA100 | Confirmed | In CISA | 28 Jan 2022 |
|
CVE-2020-5135
A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by... |
SonicOS | Confirmed | In CISA | 15 Mar 2022 |
|
CVE-2019-7483
In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of... |
SMA100 | Confirmed | In CISA | 28 Mar 2022 |
|
CVE-2021-20028
Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products,... |
SonicWall SRA/SMA100 | Confirmed | In CISA | 28 Mar 2022 |
|
CVE-2024-40766
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized... |
SonicOS | Confirmed | In CISA | 09 Sep 2024 |
|
CVE-2025-23006
Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and... |
SMA1000 | Confirmed | In CISA | 24 Jan 2025 |
|
CVE-2024-53704
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication. |
SonicOS | Confirmed | In CISA | 18 Feb 2025 |
|
CVE-2021-20035
Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands... |
SMA100 | Confirmed | In CISA | 16 Apr 2025 |
Common Vulnerability Classes (CWE)
- CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 4
- CWE-121 — Stack-based Buffer Overflow 3
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 2
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 2
- CWE-287 — Improper Authentication 1
- CWE-434 — Unrestricted Upload of File with Dangerous Type 1
- CWE-502 — Deserialization of Untrusted Data 1
- CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology