Skip to content
English

Products › Brands

Brand

SonicWall: actively exploited vulnerabilities

19 vulnerabilities in SonicWall products (SMA 100 (ex-SRA), SMA 1000, Email Security…) are in CISA’s catalog of exploited vulnerabilities, 4 of them added in the last 90 days. Last added: September 2, 2026.

The brand’s general security advisories page, not the advisory for a specific vulnerability (address checked September 28, 2026).

Active CERT-FR alert: CERTFR-2026-ALE-009 — Multiples vulnérabilités dans SonicWall Secure Mobile Access

By category

Add just one SonicWall category to your radar, or open its page.

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

Affected products

  • SMA 100 (ex-SRA) 7 vulnerabilities · Firewalls and VPNs
  • SMA 1000 6 vulnerabilities · Firewalls and VPNs
  • Email Security 3 vulnerabilities · Email
  • SonicOS 3 vulnerabilities · Firewalls and VPNs

Name used by CISA: SonicWall. Product families: indicative classification by this site.

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this SonicWall list.

  1. Rank 1SonicWall SMA 1000

    CVE-2026-83548

    Recently addedActive CERT-FR alertHunt for compromise (CISA)

    SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 2, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  2. Rank 2SonicWall SMA 1000

    CVE-2026-83549

    Recently addedActive CERT-FR alertHunt for compromise (CISA)

    SonicWall SMA1000 Appliances OS Command Injection Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 2, 2026
    CISA deadline
    3 days
    CVSS severity
    7.8 (high)
  3. Rank 3SonicWall SMA 1000

    CVE-2026-15409

    Hunt for compromise (CISA)Ransomware

    SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 14, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  4. Rank 4SonicWall SMA 1000

    CVE-2026-15410

    Hunt for compromise (CISA)Ransomware

    SonicWall SMA1000 Appliances Code Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 14, 2026
    CISA deadline
    3 days
    CVSS severity
    7.2 (high)
  5. Rank 5SonicWall SMA 1000

    CVE-2025-40602

    SonicWall SMA1000 Missing Authorization Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Dec 17, 2025
    CISA deadline
    7 days
    CVSS severity
    6.6 (medium)
  6. Rank 6SonicWall SonicOS

    CVE-2024-53704

    Ransomware

    SonicWall SonicOS SSLVPN Improper Authentication Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 18, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  7. Rank 7SonicWall SMA 1000

    CVE-2025-23006

    Ransomware

    SonicWall SMA1000 Appliances Deserialization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 24, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  8. Rank 8SonicWall SonicOS

    CVE-2024-40766

    Ransomware

    SonicWall SonicOS Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 9, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  9. Rank 9SonicWall SonicOS

    CVE-2020-5135

    RansomwareCVE from 2020, added in 2022

    SonicWall SonicOS Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 15, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  10. Rank 10SonicWall SMA 100 (ex-SRA)

    CVE-2021-20038

    Ransomware

    SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 28, 2022
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
Show 8 more vulnerabilities
  1. Rank 11SonicWall SMA 100 (ex-SRA)

    CVE-2021-20016

    Ransomware

    SonicWall SSLVPN SMA100 SQL Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  2. Rank 12SonicWall Email Security

    CVE-2021-20021

    Ransomware

    SonicWall Email Security Improper Privilege Management Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  3. Rank 13SonicWall SMA 100 (ex-SRA)

    CVE-2019-7483

    CVE from 2019, added in 2022

    SonicWall SMA100 Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  4. Rank 14SonicWall SMA 100 (ex-SRA)

    CVE-2019-7481

    RansomwareCVE from 2019, added in 2021

    SonicWall SMA100 SQL Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  5. Rank 15SonicWall SMA 100 (ex-SRA)

    CVE-2023-44221

    CVE from 2023, added in 2025

    SonicWall SMA100 Appliances OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 1, 2025
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  6. Rank 16SonicWall Email Security

    CVE-2021-20022

    Ransomware

    SonicWall Email Security Unrestricted Upload of File Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.2 (high)
  7. Rank 17SonicWall SMA 100 (ex-SRA)

    CVE-2021-20035

    CVE from 2021, added in 2025

    SonicWall SMA100 Appliances OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 16, 2025
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  8. Rank 18SonicWall Email Security

    CVE-2021-20023

    Ransomware

    SonicWall Email Security Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    4.9 (medium)

End of life: remove

These products are no longer supported: no patch is coming. Remove them or isolate them from the network.

  1. SonicWall SMA 100 (ex-SRA)

    CVE-2021-20028

    RansomwareEnd of life

    SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)

Follow and verify

Get new SonicWall vulnerabilities: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.