SonicWall known exploited vulnerabilities
CISA lists 19 SonicWall CVEs as exploited in the wild. 5 were added in the last 12 months (latest 2026-09-02), and 13 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2021-20038 (SMA 100 Appliances): EPSS 99.9%, added 2022-01-28
- CVE-2019-7481 (SMA100): EPSS 99.9%, added 2021-11-03
- CVE-2024-53704 (SonicOS): EPSS 95.1%, added 2025-02-18
- CVE-2021-20021 (SonicWall Email Security): EPSS 88.7%, added 2021-11-03
- CVE-2023-44221 (SMA100 Appliances): EPSS 76.2%, added 2025-05-01
Most affected SonicWall products
SMA1000 Appliances (5), SonicOS (3), SonicWall Email Security (3), SMA100 Appliances (2), SMA100 (2), SMA1000 appliance (1), Secure Remote Access (SRA) (1), SMA 100 Appliances (1), SSLVPN SMA100 (1).
All SonicWall CVEs in KEV
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2026-83549 | SMA1000 Appliances | SMA1000 Appliances OS Command Injection | 2026-09-02 | 2026-09-05 | 10.8% | – |
| CVE-2026-83548 | SMA1000 Appliances | SMA1000 Appliances Server-Side Request Forgery | 2026-09-02 | 2026-09-05 | 8.8% | – |
| CVE-2026-15410 | SMA1000 Appliances | SMA1000 Appliances Code Injection | 2026-07-14 | 2026-07-17 | 11.8% | Yes |
| CVE-2026-15409 | SMA1000 Appliances | SMA1000 Appliances Server-Side Request Forgery | 2026-07-14 | 2026-07-17 | 6.8% | Yes |
| CVE-2025-40602 | SMA1000 appliance | SMA1000 Missing Authorization | 2025-12-17 | 2025-12-24 | 2.8% | – |
| CVE-2023-44221 | SMA100 Appliances | SMA100 Appliances OS Command Injection | 2025-05-01 | 2025-05-22 | 76.2% | – |
| CVE-2021-20035 | SMA100 Appliances | SMA100 Appliances OS Command Injection | 2025-04-16 | 2025-05-07 | 4.2% | – |
| CVE-2024-53704 | SonicOS | SonicOS SSLVPN Improper Authentication | 2025-02-18 | 2025-03-11 | 95.1% | Yes |
| CVE-2025-23006 | SMA1000 Appliances | SMA1000 Appliances Deserialization | 2025-01-24 | 2025-02-14 | 23.4% | Yes |
| CVE-2024-40766 | SonicOS | SonicOS Improper Access Control | 2024-09-09 | 2024-09-30 | 18.4% | Yes |
| CVE-2021-20028 | Secure Remote Access (SRA) | Secure Remote Access (SRA) SQL Injection | 2022-03-28 | 2022-04-18 | 30.1% | Yes |
| CVE-2019-7483 | SMA100 | SMA100 Directory Traversal | 2022-03-28 | 2022-04-18 | 4.0% | – |
| CVE-2020-5135 | SonicOS | SonicOS Buffer Overflow | 2022-03-15 | 2022-04-05 | 26.9% | Yes |
| CVE-2021-20038 | SMA 100 Appliances | SMA 100 Appliances Stack-Based Buffer Overflow | 2022-01-28 | 2022-02-11 | 99.9% | Yes |
| CVE-2021-20023 | SonicWall Email Security | Email Security Path Traversal | 2021-11-03 | 2021-11-17 | 51.4% | Yes |
| CVE-2021-20022 | SonicWall Email Security | Email Security Unrestricted Upload of File | 2021-11-03 | 2021-11-17 | 16.5% | Yes |
| CVE-2021-20021 | SonicWall Email Security | Email Security Improper Privilege Management | 2021-11-03 | 2021-11-17 | 88.7% | Yes |
| CVE-2021-20016 | SSLVPN SMA100 | SSLVPN SMA100 SQL Injection | 2021-11-03 | 2021-11-17 | 40.0% | Yes |
| CVE-2019-7481 | SMA100 | SMA100 SQL Injection | 2021-11-03 | 2022-05-03 | 99.9% | Yes |
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.
Read next: Which CVEs to patch first this week · All vendors