VulnSea

SonicWall has 13 CVEs on record between 2019 and 2026. 5 were published in the last 90 days. The busiest recent month was October 2026 with 4. The median CVSS is 9.8 (critical), with 5 rated critical. 69% have been exploited in the wild — well above the 1% corpus average, so SonicWall flaws are worth patching on sight. The median gap from publication to a KEV listing is 197 days (9 cases). Most affected products: SMA1000 (4), email_security (3), sma8200v (2).

CVEs per month

Last 12 months, by publish date

111201020304050607080910
Exploited share
69% vs 1% corpus
Median CVSS
9.8
Publish → KEV
197 d median(9)
Last 90 days
5 prev 0

Products

  • SMA1000 4
  • email_security 3
  • sma8200v 2
  • sonicos 2
  • sma_100_firmware 1
  • sma_500v 1
13
Total CVEs
5
Critical
9
CISA KEV
9
Exploited

SonicWall vulnerabilities

CVEs affecting SonicWall, newest first. Open any entry for full detail, references, and exploit status.

13 CVEsRSS

CVE-2026-102258None
today

Post-authentication Stored Cross-Site Scripting (XSS) vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administra…

Post-authentication Stored Cross-Site Scripting (XSS) vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administra…

▾ SunlitSonicWall · SMA1000via NVD
CVE-2026-102257None
today

A Zip Slip vulnerability in the in the SMA1000 Appliance Management Console (AMC) interface allows an attacker to extract files outside the intended destination directory using a specially crafted archive, resulting in remote code execut…

A Zip Slip vulnerability in the in the SMA1000 Appliance Management Console (AMC) interface allows an attacker to extract files outside the intended destination directory using a specially crafted archive, resulting in remote code execut…

▾ SunlitSonicWall · SMA1000via NVD
CVE-2026-102256None
today

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 appliance which in specific conditions could potentially enable a remote auth…

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 appliance which in specific conditions could potentially enable a remote auth…

▾ SunlitSonicWall · SMA1000via NVD
CVE-2026-102255None
today

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability…

▾ SunlitSonicWall · SMA1000via NVD
CVE-2026-83549High· 7.8CISA KEV0dayPoC
1mo ago

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potenti…

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potenti…

▾ Abyssalsonicwall · sma8200vEPSS 11%via NVD
CVE-2025-23006Critical· 9.8CISA KEV0day
1y ago

Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote…

Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote…

▾ Hadalsonicwall · sma8200vEPSS 23%via NVD
CVE-2024-53704Critical· 9.8CISA KEVPoC
1y ago

An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

▾ Hadalsonicwall · sonicosEPSS 95%via NVD
CVE-2024-40766Critical· 9.8CISA KEVPoC
2y ago

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects So…

▾ Hadalsonicwall · sonicosEPSS 18%via NVD
CVE-2021-20023Medium· 4.9CISA KEVPoC
5y ago

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.

▾ Midnightsonicwall · email_securityEPSS 52%via NVD
CVE-2021-20022High· 7.2CISA KEVPoC
5y ago

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.

▾ Abyssalsonicwall · email_securityEPSS 17%via NVD
CVE-2021-20021Critical· 9.8CISA KEVPoC
5y ago

A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.

A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.

▾ Hadalsonicwall · email_securityEPSS 89%via NVD
CVE-2021-20016Critical· 9.8CISA KEV0day
5y ago

A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information

A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build…

▾ Hadalsonicwall · sma_500vEPSS 40%via NVD
CVE-2019-7481High· 7.5CISA KEVPoC
6y ago

Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources

Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity impacted SMA100 version 9.0.0.3 and earlier.

▾ Abyssalsonicwall · sma_100_firmwareEPSS 100%via NVD
SonicWall vulnerabilities (CVEs) · VulnSea