SonicWall Firewall and Security firm
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any SonicWall product.
RSS Feeds for SonicWall security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in SonicWall products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by SonicWall Sorted by Most Security Vulnerabilities since 2018
Known Exploited SonicWall Vulnerabilities
The following SonicWall vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| SonicWall SMA1000 Appliances Code Injection Vulnerability |
SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands. CVE-2026-15410 Exploit Probability: 76.3% |
July 14, 2026 |
| SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability |
SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location. CVE-2026-15409 Exploit Probability: 78.4% |
July 14, 2026 |
| SonicWall SMA1000 Missing Authorization Vulnerability |
SonicWall SMA1000 contains a missing authorization vulnerability that could allow for privilege escalation appliance management console (AMC) of affected devices. CVE-2025-40602 Exploit Probability: 2.0% |
December 17, 2025 |
| SonicWall SMA100 Appliances OS Command Injection Vulnerability |
SonicWall SMA100 appliances contain an OS command injection vulnerability in the SSL-VPN management interface that allows a remote, authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user. CVE-2023-44221 Exploit Probability: 74.9% |
May 1, 2025 |
| SonicWall SMA100 Appliances OS Command Injection Vulnerability |
SonicWall SMA100 appliances contain an OS command injection vulnerability in the management interface that allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user, which could potentially lead to code execution. CVE-2021-20035 Exploit Probability: 4.1% |
April 16, 2025 |
| SonicWall SonicOS SSLVPN Improper Authentication Vulnerability |
SonicWall SonicOS contains an improper authentication vulnerability in the SSLVPN authentication mechanism that allows a remote attacker to bypass authentication. CVE-2024-53704 Exploit Probability: 95.1% |
February 18, 2025 |
| SonicWall SMA1000 Appliances Deserialization Vulnerability |
SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) contain a deserialization of untrusted data vulnerability, which can enable a remote, unauthenticated attacker to execute arbitrary OS commands. CVE-2025-23006 Exploit Probability: 23.4% |
January 24, 2025 |
| SonicWall SonicOS Improper Access Control Vulnerability |
SonicWall SonicOS contains an improper access control vulnerability that could lead to unauthorized resource access and, under certain conditions, may cause the firewall to crash. CVE-2024-40766 Exploit Probability: 18.2% |
September 9, 2024 |
| SonicWall SMA100 Directory Traversal Vulnerability |
In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server. CVE-2019-7483 Exploit Probability: 4.0% |
March 28, 2022 |
| SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability |
SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection. CVE-2021-20028 Exploit Probability: 29.9% |
March 28, 2022 |
| SonicWall SonicOS Buffer Overflow Vulnerability |
A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall. CVE-2020-5135 Exploit Probability: 26.9% |
March 15, 2022 |
| SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability |
SonicWall SMA 100 devies are vulnerable to an unauthenticated stack-based buffer overflow vulnerability where exploitation can result in code execution. CVE-2021-20038 Exploit Probability: 99.9% |
January 28, 2022 |
| SonicWall Email Security Privilege Escalation Exploit Chain |
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. CVE-2021-20021 Exploit Probability: 83.4% |
November 3, 2021 |
| SonicWall SSL VPN SMA100 SQL Injection Vulnerability |
Allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information in SMA100 build version 10.x. CVE-2021-20016 Exploit Probability: 40.0% |
November 3, 2021 |
| SonicWall Email Security Privilege Escalation Exploit Chain |
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host. CVE-2021-20023 Exploit Probability: 51.4% |
November 3, 2021 |
| SonicWall Email Security Privilege Escalation Exploit Chain |
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host. CVE-2021-20022 Exploit Probability: 16.5% |
November 3, 2021 |
| SonicWall SMA100 9.0.0.3 and Earlier SQL Injection |
Vulnerability in SonicWall SMA100 versions 9.0.0.3 and earlier allow an unauthenticated user to gain read-only access to unauthorized resources. CVE-2019-7481 Exploit Probability: 99.9% |
November 3, 2021 |
Of the known exploited vulnerabilities above, 7 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings. 7 known exploited SonicWall vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.
By the Year
In 2026 there have been 29 vulnerabilities in SonicWall with an average score of 6.9 out of ten. Last year, in 2025 SonicWall had 20 security vulnerabilities published. That is, 9 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.45
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 29 | 6.89 |
| 2025 | 20 | 7.34 |
| 2024 | 11 | 7.93 |
| 2023 | 32 | 7.69 |
| 2022 | 7 | 8.15 |
| 2021 | 34 | 7.79 |
| 2020 | 15 | 7.01 |
| 2019 | 21 | 8.07 |
| 2018 | 3 | 6.90 |
It may take a day or so for new SonicWall vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent SonicWall Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-66153 | Aug 25, 2026 |
SonicWall NetExtender Linux Client Temp File Path Manipulation in Auto-UpgradeThe NEService auto-upgrade process insecurely handles temporary files in SonicWall NetExtender Linux client which allows an attacker to manipulate file paths. |
|
| CVE-2026-66152 | Aug 25, 2026 |
SonicWall NetExtender: Path Traversal Enables Root Write via tarballA Path traversal vulnerability in OPSWAT tarball in the SonicWall NetExtender Linux client allows an attacker to write arbitrary file as root. |
|
| CVE-2026-66150 | Aug 11, 2026 |
SonicWall Email Security CLI: Code Injection via SNMP as RootImproper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via SNMP. |
|
| CVE-2026-66149 | Aug 11, 2026 |
SonicWall Email Security: Code Injection via netmask CLI (CVE-2026-66149)Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via netmask. |
|
| CVE-2026-18634 | Aug 11, 2026 |
SonicWall GMS <=9.5.1 insecure serialized objects (CVE-2026-18634)An insecure handling of serialized objects vulnerability was found in the one of the service of GMS application 9.5.1 (Build 9510.1044) and earlier versions. A local attacker with the ability to interact with the service could exploit this behavior to perform unauthorized actions through the affected component. |
|
| CVE-2026-66154 | Aug 11, 2026 |
Insufficient Cert Validation in SonicWall GMS 9.5.1 (Privileged Workflow)An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1 (Build 9510.1044) and earlier versions which, under a successful MitM attack and controlled network conditions, could permit unauthorized changes. |
|
| CVE-2026-66148 | Aug 11, 2026 |
Cmd injection in SonicWall GMS CLI <9.5.1An authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.1044) and earlier versions which allows low-privileged local user to execute system commands with root privileges. |
|
| CVE-2026-66147 | Aug 11, 2026 |
CVE-2026-66147: GMS 9.5.1 Command Injection via DispatcherAn unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests. |
|
| CVE-2026-66146 | Aug 11, 2026 |
SonicWall GMS 9.5.x XSS Enables Remote JS ExecutionMultiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.5.1 (Build 9510.1044) and earlier versions that allow a remote attacker to execute javascript script in a user's browser. |
|
| CVE-2026-66145 | Aug 11, 2026 |
Unauthenticated RCE via ZipSlip in SonicWall GMS <9.5.1An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip. |
|
| CVE-2026-66151 | Aug 07, 2026 |
SonicWall Global VPN Client <4.10.8.1108: SWIPsec.sys OOB Read CrashSonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec.sys driver, which could allow a local attacker to cause a system crash. |
|
| CVE-2026-0516 | Aug 05, 2026 |
HTTP Header Injection in SonicOS Allows Host Header ManipulationA improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header and redirect firewall management users to arbitrary web domains. |
|
| CVE-2026-15410 | Jul 14, 2026 |
SonicWall SMA1000 AMC: Authenticated Code Injection (OS Exec)Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands. |
|
| CVE-2026-15409 | Jul 14, 2026 |
SSRF Vulnerability in SonicWall SMA1000 Appliance Work PlaceA Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location. |
|
| CVE-2026-0206 | Apr 29, 2026 |
SonicOS Post-Auth Stack Buf Overflow CrashA post-authentication Stack-based Buffer Overflow vulnerabilities in SonicOS allows a remote attacker to crash a firewall. |
|
| CVE-2026-0205 | Apr 29, 2026 |
Post-Auth Path Traversal in SonicOSA post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted services. |
|
| CVE-2026-0204 | Apr 29, 2026 |
SonicOS AMI Access Control Bypass (CVE-2026-0204)A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions. |
|
| CVE-2026-4116 | Apr 09, 2026 |
SonicWall SMA1000 SSLVPN TOTP Bypass via Unicode Encoding FlawImproper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user to bypass Workplace/Connect Tunnel TOTP authentication. |
|
| CVE-2026-4114 | Apr 09, 2026 |
SonicWall SMA1000 Auth Bypass via Unicode in SSLVPN TOTPImproper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin to bypass AMC TOTP authentication. |
|
| CVE-2026-4113 | Apr 09, 2026 |
SSL VPN Credential Enumeration in SonicWall SMA1000An observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances allows a remote attacker to enumerate SSL VPN user credentials. |
|
| CVE-2026-4112 | Apr 09, 2026 |
SonicWall SMA1000 Series SQLi Remote Auth Priv EscalationImproper neutralization of special elements used in an SQL command (SQL Injection) in SonicWall SMA1000 series appliances allows a remote authenticated attacker with read-only administrator privileges to escalate privileges to primary administrator. |
|
| CVE-2026-3470 | Mar 31, 2026 |
SonicWall Email Security: Remote Auth DB Corruption via Improper Input Sanit.A vulnerability exists in the SonicWall Email Security appliance due to improper input sanitization that may lead to data corruption, allowing a remote authenticated attacker as admin user could exploit this issue by providing crafted input that corrupts application database. |
|
| CVE-2026-3469 | Mar 31, 2026 |
DoS via Validation in SonicWall Email Security ApplianceA denial-of-service (DoS) vulnerability exists due to improper input validation in the SonicWall Email Security appliance, allowing a remote authenticated attacker as admin user to cause the application to become unresponsive. |
|
| CVE-2026-3468 | Mar 31, 2026 |
Stored XSS in SonicWall Email Security appliance via web page genA stored Cross-Site Scripting (XSS) vulnerability has been identified in the SonicWall Email Security appliance due to improper neutralization of user-supplied input during web page generation, allowing a remote authenticated attacker as admin user to potentially execute arbitrary JavaScript code. |
|
| CVE-2026-3439 | Mar 04, 2026 |
SonicOS Stack-Based Buffer Overflow in Cert Handling Enables CrashA post-authentication Stack-based Buffer Overflow vulnerability in SonicOS certificate handling allows a remote attacker to crash a firewall. |
|
| CVE-2026-0402 | Feb 24, 2026 |
SonicOS Post-Auth OOB Read Crash VulnerabilityA post-authentication Out-of-bounds Read vulnerability in SonicOS allows a remote attacker to crash a firewall. |
|
| CVE-2026-0401 | Feb 24, 2026 |
NULL Pointer Deref in SonicOS Firewall PostAuth Crash VulnerabilityA post-authentication NULL Pointer Dereference vulnerability in SonicOS allows a remote attacker to crash a firewall. |
|
| CVE-2026-0400 | Feb 24, 2026 |
SonicOS Post-Auth Format String Crash CVE-2026-0400A post-authentication Format String vulnerability in SonicOS allows a remote attacker to crash a firewall. |
|
| CVE-2026-0399 | Feb 24, 2026 |
SonicOS API stack buffer overflow (post-auth)Multiple post-authentication stack-based buffer overflow vulnerabilities in the SonicOS management interface due to improper bounds checking in a API endpoint. |
|
| CVE-2025-40602 | Dec 18, 2025 |
SonicWall SMA1000 AMC LPE via Insufficient AuthA local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC). |
|
| CVE-2025-40601 | Nov 20, 2025 |
SonicOS SSLVPN Buffer Overflow Remote Unauth DoSA Stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted firewall to crash. |
|
| CVE-2025-40605 | Nov 20, 2025 |
Email Sec Appliance Path Traversal Unauthorized File AccessA Path Traversal vulnerability has been identified in the Email Security appliance allows an attacker to manipulate file system paths by injecting crafted directory-traversal sequences (such as ../) and may access files and directories outside the intended restricted path. |
|
| CVE-2025-40604 | Nov 20, 2025 |
SonicWall Email Security Appliance: Root FS Image Integrity Check BypassDownload of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signatures, allowing attackers with VMDK or datastore access to modify system files and gain persistent arbitrary code execution. |
|
| CVE-2025-40603 | Oct 31, 2025 |
SonicWall SMA100 Remote Auth Admin Log Info Leak (CVE-2025-40603)A potential exposure of sensitive information in log files in SonicWall SMA100 Series appliances may allow a remote, authenticated administrator, under certain conditions to view partial users credential data. |
|
| CVE-2025-40600 | Jul 29, 2025 |
SonicOS SSL VPN Format String Causing DoSUse of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service disruption. |
|
| CVE-2025-32821 | May 07, 2025 |
SMA100 SSLVPN Command Injection: File Upload by Authenticated AttackerA vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN admin privileges can with admin privileges can inject shell command arguments to upload a file on the appliance. |
|
| CVE-2025-32819 | May 07, 2025 |
SMA100 SSLVPN Auth Path Traversal File Deletion (CVE-2025-32819)A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings. |
|
| CVE-2025-2170 | Apr 30, 2025 |
SSRF in SMA1000 WorkPlace Interface Allows Remote UnAuth RequestsA Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface, which in specific conditions could potentially enable a remote unauthenticated attacker to cause the appliance to make requests to an unintended location. |
|
| CVE-2025-32818 | Apr 23, 2025 |
SonicOS SSLVPN Virtual Office NPE in SSLVPN Interface allows Remote DoSA Null Pointer Dereference vulnerability in the SonicOS SSLVPN Virtual office interface allows a remote, unauthenticated attacker to crash the firewall, potentially leading to a Denial-of-Service (DoS) condition. |
|
| CVE-2025-23010 | Apr 10, 2025 |
Link Following in SonicWall NetExtender Windows ClientAn Improper Link Resolution Before File Access ('Link Following') vulnerability in SonicWall NetExtender Windows (32 and 64 bit) client which allows an attacker to manipulate file paths. |
|
| CVE-2025-23009 | Apr 10, 2025 |
CVE-2025-23009: LPE in SonicWall NetExtender (32/64-bit) -> File DeleteA local privilege escalation vulnerability in SonicWall NetExtender Windows (32 and 64 bit) client which allows an attacker to trigger an arbitrary file deletion. |
|
| CVE-2025-23006 | Jan 23, 2025 |
Remote OS Command Exec via Pre-auth Deserialization in SMA1000 AMC/CMCPre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands. |
|
| CVE-2024-12802 | Jan 09, 2025 |
SonicWALL SSLVPN MFA Bypass via UPN/SAM SplittingSSL-VPN MFA Bypass in SonicWALL SSL-VPN can arise in specific cases due to the separate handling of UPN (User Principal Name) and SAM (Security Account Manager) account names when integrated with Microsoft Active Directory, allowing MFA to be configured independently for each login method and potentially enabling attackers to bypass MFA by exploiting the alternative account name. |
|
| CVE-2024-12806 | Jan 09, 2025 |
SonicOS Admin Absolute Path Traversal Enables Post-Auth File ReadA post-authentication absolute path traversal vulnerability in SonicOS management allows a remote attacker to read an arbitrary file. |
|
| CVE-2024-40765 | Jan 09, 2025 |
Integer Overflow in SonicOS IPSec (IKEv2) Remote DoS/ExecAn Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a specially crafted IKEv2 payload. |
|
| CVE-2024-12803 | Jan 09, 2025 |
SonicOS CLI Buffer Overflow Enables Remote CrashA post-authentication stack-based buffer overflow vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution. |
|
| CVE-2024-12805 | Jan 09, 2025 |
SonicOS Post-Auth Format String Vulnerability Enables Crash & RCEA post-authentication format string vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution. |
|
| CVE-2024-53705 | Jan 09, 2025 |
SSRF in SonicOS SSH Mgmt Enables Remote TCP ConnectionsA Server-Side Request Forgery vulnerability in the SonicOS SSH management interface allows a remote attacker to establish a TCP connection to an IP address on any port when the user is logged in to the firewall. |
|
| CVE-2024-53704 | Jan 09, 2025 |
Improper Auth in SSLVPN auth bypass vulnerabilityAn Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication. |
|
| CVE-2024-40766 | Aug 23, 2024 |
SonicWall SonicOS 7.0.1-5035 MM Access Control VulnerabilityAn improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions. |
|