VulnSea

sonicwall has 8 CVEs on record between 2019 and 2026. 1 was published in the last 90 days. The median CVSS is 8.8 (high), with 4 rated critical. 100% have been exploited in the wild — well above the 1% corpus average, so sonicwall flaws are worth patching on sight. The median gap from publication to a KEV listing is 203 days (8 cases). Most affected products: email_security (3), sma8200v (2), sma_100_firmware (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
100% vs 1% corpus
Median CVSS
8.8
Publish → KEV
203 d median(8)
Last 90 days
1 prev 0

Products

  • email_security 3
  • sma8200v 2
  • sma_100_firmware 1
  • sma_500v 1
  • sonicos 1
8
Total CVEs
4
Critical
8
CISA KEV
8
Exploited

sonicwall vulnerabilities

CVEs affecting sonicwall, newest first. Open any entry for full detail, references, and exploit status.

8 CVEsRSS

CVE-2026-83549High· 7.8CISA KEV0dayPoC
2w ago

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potenti…

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potenti…

Abyssalsonicwall · sma8200vEPSS 8.5%via NVD
CVE-2025-23006Critical· 9.8CISA KEV0day
1y ago

Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote…

Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote…

Hadalsonicwall · sma8200vEPSS 23%via NVD
CVE-2024-53704Critical· 9.8CISA KEVPoC
1y ago

An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

Hadalsonicwall · sonicosEPSS 95%via NVD
CVE-2021-20023Medium· 4.9CISA KEV0day
5y ago

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.

Midnightsonicwall · email_securityEPSS 51%via NVD
CVE-2021-20022High· 7.2CISA KEV
5y ago

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.

Abyssalsonicwall · email_securityEPSS 17%via NVD
CVE-2021-20021Critical· 9.8CISA KEVPoC
5y ago

A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.

A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.

Hadalsonicwall · email_securityEPSS 83%via NVD
CVE-2021-20016Critical· 9.8CISA KEV0day
5y ago

A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information

A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build…

Hadalsonicwall · sma_500vEPSS 40%via NVD
CVE-2019-7481High· 7.5CISA KEVPoC
6y ago

Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources

Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity impacted SMA100 version 9.0.0.3 and earlier.

Abyssalsonicwall · sma_100_firmwareEPSS 100%via NVD
sonicwall vulnerabilities (CVEs) · VulnSea