SonicWall Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for SonicWall products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

21

In CISA KEV

17

Beyond CISA KEV

4

Sensor Observed

2

Virtual Patch Available

1

SonicWall KEVs Added by Year

Loading...

21 SonicWall KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2026-15410

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management...

Confirmed In CISA 14 Jul 2026
CVE-2026-15409

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated...

Confirmed In CISA 14 Jul 2026
CVE-2023-34133

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SonicWall GMS and Analytics allows an...

High Not in CISA 07 Jul 2025
CVE-2025-40602

A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).

Confirmed In CISA 01 Jun 2026
CVE-2023-44221

Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative...

Confirmed In CISA 01 May 2025
CVE-2018-9866

A vulnerability in lack of validation of user-supplied parameters pass to XML-RPC calls on SonicWall Global Management System (GMS) virtual...

High Not in CISA 26 Apr 2025
CVE-2022-22274

A Stack-based buffer overflow vulnerability in the SonicOS via HTTP request allows a remote unauthenticated attacker to cause Denial of Service...

High Not in CISA 28 Apr 2025
CVE-2023-0656

A Stack-based buffer overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could...

High Not in CISA 28 Apr 2025
CVE-2021-20016

A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access...

Confirmed In CISA 03 Nov 2021
CVE-2021-20023

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the...

Confirmed In CISA 03 Nov 2021
CVE-2021-20022

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the...

Confirmed In CISA 03 Nov 2021
CVE-2019-7481

Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity impacted SMA100...

Confirmed In CISA 03 Nov 2021
CVE-2021-20021

A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP...

Confirmed In CISA 03 Nov 2021
CVE-2021-20038

A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated...

Confirmed In CISA 28 Jan 2022
CVE-2020-5135

A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by...

Confirmed In CISA 15 Mar 2022
CVE-2019-7483

In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of...

Confirmed In CISA 28 Mar 2022
CVE-2021-20028

Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products,...

Confirmed In CISA 28 Mar 2022
CVE-2024-40766

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized...

Confirmed In CISA 09 Sep 2024
CVE-2025-23006

Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and...

Confirmed In CISA 24 Jan 2025
CVE-2024-53704

An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

Confirmed In CISA 18 Feb 2025
CVE-2021-20035

Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands...

Confirmed In CISA 16 Apr 2025

Common Vulnerability Classes (CWE)

  • CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 4
  • CWE-121 — Stack-based Buffer Overflow 3
  • CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 2
  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 2
  • CWE-287 — Improper Authentication 1
  • CWE-434 — Unrestricted Upload of File with Dangerous Type 1
  • CWE-502 — Deserialization of Untrusted Data 1
  • CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology