PatchSiren

SonicWall CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Known exploited SonicWall CVE published 2026-09-02

CVE-2026-83549

A SonicWall SMA1000 Appliances OS Command Injection Vulnerability was added to the CISA Known Exploited Vulnerabilities catalog on 2026-09-02. This HIGH severity vulnerability has a CVSS score of 7.8. The vulnerability affects SonicWall SMA1000 Appliances and requires immediate attention from administrators. It is crucial to assess potential for OS command injection attacks and prioritize patching based o [truncated]

HIGH SonicWall CVE published 2026-08-11

CVE-2026-66150

CVE-2026-66150 is an Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance. An authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via SNMP. This vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. Organizations should prioritize patching to [truncated]

MEDIUM SonicWall CVE published 2026-08-11

CVE-2026-66148

Authenticated command injection vulnerability in GMS Command-Line Interface (CLI) 9.5.1 and earlier allows low-privileged local users to execute system commands with root privileges. This vulnerability, CVE-2026-66148, is considered medium severity with a CVSS score of 6.3. It was identified in the GMS CLI versions 9.5.1 and earlier, impacting local users who can execute system commands with elevated priv [truncated]

CRITICAL SonicWall CVE published 2026-08-11

CVE-2026-66147

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-11T21:17:49.173Z and has not been modified since then. This critical vulnerability, CVE-2026-66147, is an unauthenticated command injection vulnerability in the GMS Dispatcher Service of GMS 9.5.1 and earlier versions. It allows remote attackers to perform remote code execution through specially cra [truncated]

HIGH SonicWall CVE published 2026-08-11

CVE-2026-18634

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-11T21:17:30.880Z and has not been modified since then. The insecure handling of serialized objects vulnerability in GMS application 9.5.1 (Build 9510.1044) and earlier versions allows a local attacker to perform unauthorized actions through the affected component. Organizations should prioritize pat [truncated]

MEDIUM SonicWall CVE published 2026-08-11

CVE-2026-66146

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-11T20:18:37.837Z and has not been modified since then. Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.5.1 (Build 9510.1044) and earlier versions. These vulnerabilities allow a remote attacker to execute JavaScript script in a user's browser. Organizations using GMS 9.5. [truncated]

CRITICAL SonicWall CVE published 2026-08-11

CVE-2026-66145

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-11T20:18:37.717Z and has not been modified since then. The vulnerability allows remote attackers to read sensitive data and perform arbitrary file writes via zipslip. Organizations using GMS 9.5.1 (Build 9510.1044) or earlier should be aware of this vulnerability and take steps to mitigate it. Evide [truncated]

MEDIUM SonicWall CVE published 2026-08-05

CVE-2026-0516

A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header and redirect firewall management users to arbitrary web domains. This vulnerability, tracked as CVE-2026-0516, was published on 2026-08-05T13:20:33.670Z. The affected product is SonicOS, and the vulnerability class is related to improper neutralization of HTTP [truncated]

Known exploited SonicWall CVE published 2026-07-14

CVE-2026-15410

PatchSiren debrief for CVE-2026-15410: SonicWall SMA1000 Appliances Code Injection Vulnerability. Defenders should assess exposure of SonicWall SMA1000 Appliances and apply mitigations to prevent potential code execution and disruption of critical infrastructure. The vulnerability allows attackers to execute arbitrary code on vulnerable devices, potentially disrupting critical infrastructure. Defenders re [truncated]

Known exploited SonicWall CVE published 2026-07-14

CVE-2026-15409

A critical vulnerability exists in SonicWall SMA1000 Appliances, allowing for Server-Side Request Forgery (SSRF). This vulnerability is known to be exploited in the wild and has been added to the CISA Known Exploited Vulnerabilities catalog. The vulnerability has a critical CVSS score of 10, indicating a high severity level. Defenders and administrators responsible for SonicWall SMA1000 Appliances should [truncated]

MEDIUM SonicWall CVE published 2026-04-09

CVE-2026-4114

CVE-2026-4114 is a SonicWall SMA1000 issue where improper handling of Unicode encoding can let a remote authenticated SSLVPN admin bypass AMC TOTP authentication. The NVD record cites CWE-176 and rates the issue CVSS 6.6/Medium, with an AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H vector. Because the affected path involves remote administrative access, organizations should treat it as a high-priority fix for expos [truncated]

HIGH SonicWall CVE published 2026-04-09

CVE-2026-4112

CVE-2026-4112 affects SonicWall SMA1000 series appliances and was published on 2026-04-09. According to the public description, a remote authenticated attacker with read-only administrator privileges can abuse an SQL injection weakness to escalate to primary administrator. That combination of authenticated access and full privilege gain makes this a serious management-plane issue for any environment that [truncated]

LOW SonicWall CVE published 2026-03-31

CVE-2026-3470

A vulnerability exists in the SonicWall Email Security appliance due to improper input sanitization, which may lead to data corruption. An authenticated attacker with admin privileges could exploit this issue by providing crafted input that corrupts the application database. The vulnerability has a CVSS score of 3.8, indicating a low severity. Administrators and security teams responsible for SonicWall Em [truncated]

MEDIUM SonicWall CVE published 2026-03-31

CVE-2026-3468

A stored Cross-Site Scripting (XSS) vulnerability has been identified in the SonicWall Email Security appliance due to improper neutralization of user-supplied input during web page generation. This allows a remote authenticated attacker as an admin user to potentially execute arbitrary JavaScript code. The vulnerability exists in the SonicWall Email Security appliance and is caused by improper neutraliza [truncated]

Known exploited SonicWall CVE published 2025-12-17

CVE-2025-40602

CVE-2025-40602 is a SonicWall SMA1000 appliance missing authorization vulnerability that was added to CISA’s Known Exploited Vulnerabilities catalog on 2025-12-17. Because it is a KEV-listed issue, defenders should treat it as a high-priority remediation item, especially for any internet-accessible SMA1000 deployments. CISA’s guidance is to apply vendor mitigations, follow applicable BOD 22-01 guidance fo [truncated]

Known exploited SonicWall CVE published 2025-05-01

CVE-2023-44221

CVE-2023-44221 is an OS command injection issue affecting SonicWall SMA100 Appliances. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-05-01, which means defenders should treat it as actively exploited and prioritize remediation. The supplied corpus does not provide affected-version details or a CVSS score, so the safest response is to follow SonicWall mitigation guidance, confirm whe [truncated]

Known exploited SonicWall CVE published 2025-04-16

CVE-2021-20035

CVE-2021-20035 is a SonicWall SMA100 Appliances OS command injection vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2025-04-16. A KEV listing means the issue is known to be actively exploited, so affected environments should treat it as a high-priority exposure. CISA’s entry directs organizations to apply vendor mitigations, follow BOD 22-01 guidance for cloud services whe [truncated]

Known exploited SonicWall CVE published 2025-02-18

CVE-2024-53704

CVE-2024-53704 is a SonicWall SonicOS SSLVPN improper authentication issue that CISA lists in its Known Exploited Vulnerabilities catalog. Because it is marked as known exploited and associated with known ransomware campaign use, organizations should treat remediation as urgent and follow vendor guidance immediately.

Known exploited SonicWall CVE published 2025-01-24

CVE-2025-23006

CVE-2025-23006 is a SonicWall SMA1000 Appliances deserialization vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2025-01-24. CISA marks it as known exploited and notes known ransomware campaign use. The public corpus provided here does not include affected version ranges or patch details, so defenders should treat this as an urgent exposure and follow SonicWall’s official g [truncated]

Known exploited SonicWall CVE published 2024-09-09

CVE-2024-40766

CVE-2024-40766 is a SonicWall SonicOS improper access control issue that CISA added to the Known Exploited Vulnerabilities catalog on 2024-09-09. CISA marks the vulnerability as known to be used in ransomware campaigns and sets a remediation due date of 2024-09-30. Because the public corpus provided here does not include a CVSS score or deeper technical detail, the safest response is to treat this as an u [truncated]

Known exploited SonicWall CVE published 2022-03-28

CVE-2021-20028

CVE-2021-20028 is a SQL injection vulnerability in SonicWall Secure Remote Access (SRA). CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-28, and the KEV record marks it as associated with known ransomware campaign use. CISA also notes the impacted product is end-of-life and should be disconnected if still in use. Because the product is legacy and the vulnerability is known to be ex [truncated]

Known exploited SonicWall CVE published 2022-03-28

CVE-2019-7483

CVE-2019-7483 is a SonicWall SMA100 directory traversal vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. In the supplied source corpus, CISA’s entry is dated 2022-03-28 and directs defenders to apply updates per vendor instructions. Because it is in KEV, it should be treated as a high-priority remediation item, especially for any exposed SMA100 deployments.

Known exploited SonicWall CVE published 2022-03-15

CVE-2020-5135

CVE-2020-5135 is a SonicWall SonicOS buffer overflow vulnerability that CISA added to its Known Exploited Vulnerabilities (KEV) catalog on 2022-03-15. CISA’s catalog entry instructs defenders to apply updates per vendor instructions, and the remediation due date in the KEV record is 2022-04-05. Because it is on the KEV list, organizations using SonicWall SonicOS should treat it as a priority patching item [truncated]

Known exploited SonicWall CVE published 2022-01-28

CVE-2021-20038

CVE-2021-20038 is a stack-based buffer overflow affecting SonicWall SMA 100 Appliances. It was published on 2022-01-28 and is included in CISA’s Known Exploited Vulnerabilities catalog, with CISA marking known ransomware campaign use. Treat this as an urgent patching and exposure review item.

Known exploited SonicWall CVE published 2021-11-03

CVE-2021-20023

CVE-2021-20023 is a SonicWall Email Security path traversal vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2021-11-03. CISA also marks it as having known ransomware campaign use and directs affected organizations to apply vendor updates, so any unpatched deployment should be treated as an urgent remediation item.

Known exploited SonicWall CVE published 2021-11-03

CVE-2021-20022

CVE-2021-20022 is a SonicWall Email Security unrestricted file upload vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2021-11-03. CISA marks it as known to be used in ransomware campaigns and directs defenders to apply updates per vendor instructions. Because SonicWall Email Security is an internet-facing security product in many environments, this issue should be treated a [truncated]

Known exploited SonicWall CVE published 2021-11-03

CVE-2021-20021

CVE-2021-20021 is a SonicWall Email Security vulnerability described as improper privilege management. CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03, which means it is treated as actively exploited and should be prioritized for remediation.

Known exploited SonicWall CVE published 2021-11-03

CVE-2021-20016

CVE-2021-20016 is a SonicWall SSLVPN SMA100 SQL injection vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2021-11-03. The same CISA record says the issue had known ransomware campaign use and directs organizations to apply vendor updates. Because this affects an internet-facing SSL VPN product and is officially tracked as known exploited, it should be treated as a high-prio [truncated]

Known exploited SonicWall CVE published 2021-11-03

CVE-2019-7481

CVE-2019-7481 is a SonicWall SMA100 SQL injection vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2021-11-03. CISA marks it as known exploited and notes known ransomware campaign use. The recommended defensive action in the KEV entry is to apply updates per vendor instructions.