Brand
SonicWall: actively exploited vulnerabilities
19 vulnerabilities in SonicWall products (SMA 100 (ex-SRA), SMA 1000, Email Security…) are in CISA’s catalog of exploited vulnerabilities, 4 of them added in the last 90 days. Last added: September 2, 2026.
The brand’s general security advisories page, not the advisory for a specific vulnerability (address checked September 28, 2026).
-
5 vulnerabilities added in the last 12 months
-
19 exploited vulnerabilities in the catalog, in total
-
2 added in the last 30 days
By category
Add just one SonicWall category to your radar, or open its page.
- Firewalls, VPNs and remote access 16 vulnerabilities
- Email 3 vulnerabilities
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
Affected products
- SMA 100 (ex-SRA) 7 vulnerabilities · Firewalls and VPNs
- SMA 1000 6 vulnerabilities · Firewalls and VPNs
- Email Security 3 vulnerabilities · Email
- SonicOS 3 vulnerabilities · Firewalls and VPNs
Name used by CISA: SonicWall. Product families: indicative classification by this site.
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this SonicWall list.
Rank 1SonicWall SMA 1000
CVE-2026-83548Recently addedActive CERT-FR alertHunt for compromise (CISA)
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
Added to the catalog less than 30 days ago: ranked by date added.
- Added
- Sep 2, 2026
- CISA deadline
- 3 days
- CVSS severity
- 10.0 (critical)
Rank 2SonicWall SMA 1000
CVE-2026-83549Recently addedActive CERT-FR alertHunt for compromise (CISA)
SonicWall SMA1000 Appliances OS Command Injection Vulnerability
Added to the catalog less than 30 days ago: ranked by date added.
- Added
- Sep 2, 2026
- CISA deadline
- 3 days
- CVSS severity
- 7.8 (high)
Rank 3SonicWall SMA 1000
CVE-2026-15409Hunt for compromise (CISA)Ransomware
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jul 14, 2026
- CISA deadline
- 3 days
- CVSS severity
- 10.0 (critical)
Rank 4SonicWall SMA 1000
CVE-2026-15410Hunt for compromise (CISA)Ransomware
SonicWall SMA1000 Appliances Code Injection Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jul 14, 2026
- CISA deadline
- 3 days
- CVSS severity
- 7.2 (high)
Rank 5SonicWall SMA 1000
CVE-2025-40602SonicWall SMA1000 Missing Authorization Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Dec 17, 2025
- CISA deadline
- 7 days
- CVSS severity
- 6.6 (medium)
Rank 6SonicWall SonicOS
CVE-2024-53704Ransomware
SonicWall SonicOS SSLVPN Improper Authentication Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Feb 18, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 7SonicWall SMA 1000
CVE-2025-23006Ransomware
SonicWall SMA1000 Appliances Deserialization Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 24, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 8SonicWall SonicOS
CVE-2024-40766Ransomware
SonicWall SonicOS Improper Access Control Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Sep 9, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 9SonicWall SonicOS
CVE-2020-5135RansomwareCVE from 2020, added in 2022
SonicWall SonicOS Buffer Overflow Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 15, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 10SonicWall SMA 100 (ex-SRA)
CVE-2021-20038Ransomware
SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 28, 2022
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
Show 8 more vulnerabilities
Rank 11SonicWall SMA 100 (ex-SRA)
CVE-2021-20016Ransomware
SonicWall SSLVPN SMA100 SQL Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
Rank 12SonicWall Email Security
CVE-2021-20021Ransomware
SonicWall Email Security Improper Privilege Management Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
Rank 13SonicWall SMA 100 (ex-SRA)
CVE-2019-7483CVE from 2019, added in 2022
SonicWall SMA100 Directory Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 28, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 14SonicWall SMA 100 (ex-SRA)
CVE-2019-7481RansomwareCVE from 2019, added in 2021
SonicWall SMA100 SQL Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 7.5 (high)
Rank 15SonicWall SMA 100 (ex-SRA)
CVE-2023-44221CVE from 2023, added in 2025
SonicWall SMA100 Appliances OS Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 1, 2025
- CISA deadline
- 21 days
- CVSS severity
- 7.2 (high)
Rank 16SonicWall Email Security
CVE-2021-20022Ransomware
SonicWall Email Security Unrestricted Upload of File Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 14 days
- CVSS severity
- 7.2 (high)
Rank 17SonicWall SMA 100 (ex-SRA)
CVE-2021-20035CVE from 2021, added in 2025
SonicWall SMA100 Appliances OS Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Apr 16, 2025
- CISA deadline
- 21 days
- CVSS severity
- 6.5 (medium)
Rank 18SonicWall Email Security
CVE-2021-20023Ransomware
SonicWall Email Security Path Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 14 days
- CVSS severity
- 4.9 (medium)
End of life: remove
These products are no longer supported: no patch is coming. Remove them or isolate them from the network.
SonicWall SMA 100 (ex-SRA)
CVE-2021-20028RansomwareEnd of life
SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Mar 28, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Follow and verify
Get new SonicWall vulnerabilities: RSS feed (add it to Outlook, Teams, Slack or your feed reader).
Indicative classification, based on the vendor and product names given by CISA. How products are classified.