Network security
SonicWall advisories: every record the registers tie to its products
In one line
60 advisories are attributed to SonicWall products in this record, covering November 2021 to July 2026, and 8 of them appear in the CISA catalogue of known exploited vulnerabilities. A further 1 register entry mentions SonicWall without naming one of its products as affected, and is excluded rather than counted. Each entry below links to the register that published it.
Attributed
60
tied to a named product
Known exploited
8
in the CISA catalogue
Rated critical
13
by the register
Last checked
Jul 18, 2026
sources re-queried
Why this list is shorter than a CVE mirror
The registers are searched by keyword, so a search for a company name returns advisories that merely mention it. A mirror publishes those. This page does not: an entry appears only when the register itself ties it to a product of SonicWall, through a reference on the vendor's own domain, the vendor named as the assigning authority, or the affected product list naming it.
1 entry did not clear that bar and is not shown. That is the difference, and it is deliberate: a page that lists another company's vulnerability under this heading is wrong in the way that matters most.
53 of the 60 records carry a CVSS base score from the register. Where none is published, none is shown, and no score is estimated.
The full list, most recently exploited and most recent first
Records held by several registers are folded into one entry with a link to each, so the same vulnerability is not counted twice. Entries listed in the CISA catalogue of known exploited vulnerabilities are shown first, because that is the one flag on this page that changes what a reader should do next.
- CVE-2025-40602criticalCVSS 6.6Known exploitedDec 18, 2025
SonicWall SMA1000 Missing Authorization Vulnerability
- CVE-2024-40766criticalKnown exploitedSep 09, 2024
SonicWall SonicOS Improper Access Control Vulnerability
- CVE-2019-7483criticalKnown exploitedMar 28, 2022
SonicWall SMA100 Directory Traversal Vulnerability
- CVE-2021-20022criticalKnown exploitedNov 03, 2021
SonicWall Email Security Unrestricted Upload of File Vulnerability
- CVE-2021-20023criticalKnown exploitedNov 03, 2021
SonicWall Email Security Path Traversal Vulnerability
- CVE-2021-20021criticalKnown exploitedNov 03, 2021
SonicWall Email Security Improper Privilege Management Vulnerability
- CVE-2019-7481criticalKnown exploitedNov 03, 2021
SonicWall SMA100 SQL Injection Vulnerability
- CVE-2021-20016criticalKnown exploitedNov 03, 2021
SonicWall SSLVPN SMA100 SQL Injection Vulnerability
- WID-SEC-2026-2346criticalCVSS 10.0Jul 15, 2026
Affected products: SonicWall SMA
- CVE-2026-15410highCVSS 7.2Jul 14, 2026
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific…
- CVE-2026-15409criticalCVSS 10.0Jul 14, 2026
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface.
- WID-SEC-2026-1313highCVSS 8.0Apr 30, 2026
Affected products: SonicWall SonicOS
- CVE-2026-0206mediumCVSS 4.9Apr 29, 2026
A post-authentication Stack-based Buffer Overflow vulnerabilities in SonicOS allows a remote attacker to crash a firewall.
- CVE-2026-0205mediumCVSS 6.8Apr 29, 2026
A post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted services.
- CVE-2026-0204highCVSS 8.0Apr 29, 2026
A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions.
- WID-SEC-2026-1012mediumCVSS 7.2Apr 10, 2026
Affected products: SonicWall SMA
- CVE-2026-4116highCVSS 7.2Apr 09, 2026
Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user to bypass Workplace/Connect Tunnel TOTP authentication.
- CVE-2026-4114mediumCVSS 6.6Apr 09, 2026
Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin to bypass AMC TOTP authentication.
- CVE-2026-4113highCVSS 7.2Apr 09, 2026
An observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances allows a remote attacker to enumerate SSL VPN user credentials.
- CVE-2026-4112highCVSS 7.2Apr 09, 2026
Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a remote authenticated attacker with read-only…
- WID-SEC-2026-0944lowCVSS 3.8Apr 01, 2026
Affected products: SonicWall Email Security
- CVE-2026-3470lowCVSS 3.8Mar 31, 2026
A vulnerability exists in the SonicWall Email Security appliance due to improper input sanitization that may lead to data corruption, allowing a remote authenticated attacker as admin user…
- CVE-2026-3469lowCVSS 2.7Mar 31, 2026
A denial-of-service (DoS) vulnerability exists due to improper input validation in the SonicWall Email Security appliance, allowing a remote authenticated attacker as admin user to cause…
- CVE-2026-3468mediumCVSS 4.8Mar 31, 2026
A stored Cross-Site Scripting (XSS) vulnerability has been identified in the SonicWall Email Security appliance due to improper neutralization of user-supplied input during web page…
- WID-SEC-2026-0495mediumCVSS 4.9Mar 05, 2026
Affected products: SonicWall SonicOS
- CVE-2026-3439mediumCVSS 4.9Mar 04, 2026
A post-authentication Stack-based Buffer Overflow vulnerability in SonicOS certificate handling allows a remote attacker to crash a firewall.
- CVE-2026-0402mediumCVSS 4.9Feb 24, 2026
A post-authentication Out-of-bounds Read vulnerability in SonicOS allows a remote attacker to crash a firewall.
- CVE-2026-0401mediumCVSS 4.9Feb 24, 2026
A post-authentication NULL Pointer Dereference vulnerability in SonicOS allows a remote attacker to crash a firewall.
- CVE-2026-0400mediumCVSS 4.9Feb 24, 2026
A post-authentication Format String vulnerability in SonicOS allows a remote attacker to crash a firewall.
- CVE-2026-0399mediumCVSS 4.9Feb 24, 2026
Multiple post-authentication stack-based buffer overflow vulnerabilities in the SonicOS management interface due to improper bounds checking in a API endpoint.
- WID-SEC-2025-2873mediumCVSS 6.6Dec 19, 2025
Affected products: SonicWall SMA
- WID-SEC-2025-2647mediumCVSS 7.2Nov 21, 2025
Affected products: SonicWall Email Security
- WID-SEC-2025-2640mediumCVSS 7.5Nov 21, 2025
Affected products: SonicWall SSL-VPN
- CVE-2025-40604mediumCVSS 6.5Nov 20, 2025
Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signatures, allowing attackers with VMDK or…
- WID-SEC-2025-2460lowCVSS 4.5Nov 03, 2025
Affected products: SonicWall SMA
- WID-SEC-2025-1670mediumCVSS 7.5Jul 30, 2025
Affected products: SonicWall SSL-VPN
- WID-SEC-2025-1629highCVSS 9.1Jul 24, 2025
Affected products: SonicWall SMA
- CVE-2025-40597highCVSS 7.5Jul 23, 2025
A Heap-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code…
- CVE-2025-40596highCVSS 7.3Jul 23, 2025
A Stack-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code…
- WID-SEC-2025-1054mediumCVSS 7.2May 15, 2025
Affected products: SonicWall SMA
- WID-SEC-2025-0984highCVSS 8.8May 08, 2025
Affected products: SonicWall SMA
- CVE-2025-32821highCVSS 7.1May 07, 2025
A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN admin privileges can with admin privileges can inject shell command arguments to upload a file on the appliance.
- CVE-2025-32819highCVSS 8.8May 07, 2025
A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversal checks and delete an arbitrary file potentially resulting in a…
- WID-SEC-2025-0918mediumCVSS 5.4May 02, 2025
Affected products: SonicWall SMA
- WID-SEC-2023-3054mediumCVSS 7.2May 02, 2025
Affected products: SonicWall SMA
- WID-SEC-2025-0874mediumCVSS 7.5Apr 24, 2025
Affected products: SonicWall SSL-VPN
- WID-SEC-2025-0025highCVSS 8.2Feb 17, 2025
Affected products: SonicWall SonicOS
- WID-SEC-2025-0174criticalCVSS 9.8Jan 24, 2025
Affected products: SonicWall SMA
- CVE-2025-23006criticalCVSS 9.8Jan 23, 2025
Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in…
- CVE-2024-12802criticalCVSS 9.1Jan 09, 2025
SSL-VPN MFA Bypass in SonicWALL SSL-VPN can arise in specific cases due to the separate handling of UPN (User Principal Name) and SAM (Security Account Manager) account names when…
- CVE-2024-53706highCVSS 7.8Jan 09, 2025
A vulnerability in the Gen7 SonicOS Cloud platform NSv, allows a remote authenticated local low-privileged attacker to elevate privileges to `root` and potentially lead to code execution.
- CVE-2024-53704highCVSS 8.2Jan 09, 2025
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.
- WID-SEC-2024-3623highCVSS 8.1Dec 06, 2024
Affected products: SonicWall SMA
- WID-SEC-2024-3150mediumCVSS 7.8Dec 02, 2024
Affected products: SonicWall SMA
- WID-SEC-2024-0610mediumCVSS 5.3Nov 25, 2024
Affected products: SonicWall SonicOS
- WID-SEC-2024-1906highCVSS 9.3Sep 11, 2024
Affected products: SonicWall SonicOS
- WID-SEC-2024-1671mediumCVSS 7.5Jul 18, 2024
Affected products: SonicWall SonicOS
- WID-SEC-2024-1413mediumCVSS 5.3Jun 20, 2024
Affected products: SonicWall SonicOS
- WID-SEC-2024-1004mediumCVSS 7.5May 02, 2024
Affected products: SonicWall GMS
- CVE-2023-41715highCVSS 8.8Oct 17, 2023
SonicOS post-authentication Improper Privilege Management vulnerability in the SonicOS SSL VPN Tunnel allows users to elevate their privileges inside the tunnel.
Which registers contributed
| Register | Operated by | Entries | Latest |
|---|---|---|---|
| European Vulnerability Database | ENISA, European Union | 28 | Jul 14, 2026 |
| CERT-Bund security advisories | BSI, Federal Republic of Germany | 26 | Jul 15, 2026 |
| Known Exploited Vulnerabilities catalogue | CISA, United States | 8 | Dec 17, 2025 |
The entry counts here are the raw register totals for SonicWall, before attribution. They are larger than the list above for exactly that reason.
Questions this page answers
How many vulnerabilities does SonicWall have?
60 advisories in this record are tied by a register to a product of SonicWall. That is not the same as the number of vulnerabilities the products contain, and no public source knows that number. It is the count of what has been found, disclosed and published, which depends on how much the products are examined and how openly the vendor discloses.
Are any SonicWall vulnerabilities being actively exploited?
8 of the 60 records here appear in the CISA catalogue of known exploited vulnerabilities, which lists flaws with confirmed exploitation in the wild. They are shown first in the list above. Whether any of them affects your deployment depends on the versions and components you run.
Why does this page show fewer CVEs for SonicWall than other sites?
Because a keyword search for a company name returns advisories about other companies' products that mention it in passing, and this page excludes those. 1 register entry names SonicWall without naming one of its products as affected. A mirror that lists them produces a longer page and a wrong number.
Where do the SonicWall advisories on this page come from?
From European Vulnerability Database (ENISA, European Union); CERT-Bund security advisories (BSI, Federal Republic of Germany); Known Exploited Vulnerabilities catalogue (CISA, United States). Every entry links back to the register that published it, and carries the date that register states. Where the same vulnerability is held by several registers it is shown once with a link to each, rather than counted twice.
Does a long advisory list mean SonicWall is insecure?
No. A register records what researchers found and what the vendor disclosed, so a widely deployed product with a working disclosure process accumulates more entries than one nobody examines. A short list can equally mean a small install base or a vendor that publishes little. This page reports the record and does not rate the vendor, because whether this is acceptable depends on your risk appetite, your compliance scope and the alternatives you are weighing.
A list of advisories is not a risk assessment
What matters is which of these touch the components you actually run, in the configuration you actually run them in, and whether that is acceptable next to the alternatives on your shortlist. DecisionOS reads the same pool against the criteria of a real decision and produces a memo that holds up in front of a board and an auditor.
The full SonicWall record, including sources and open questions
