SonicWall threat watch

SonicWall CVE coverage for firewalls, VPN, secure mobile access, and SMB edge-security appliances.

Vendor watch hub

What this page covers

The SonicWallwatch hub is a vendor-specific view inside ITECS MSP Threat Radar. We pull the latest security advisories, incidents, and known-exploited CVEs directly from the official feeds below, score each one for MSP relevance, and surface what's most likely to need attention this week.

  • Confirm whether recent SonicWall activity overlaps with your environment.
  • Prioritize advisories by MSP-relevance score, severity, and status.
  • Turn the signal into an assessment, briefing, or managed-service engagement with ITECS.

At a glance

Tracked

15

Active

15

Featured

15

Unique CVEs

15

Most recent entry

Dec 16, 2025, 6:00 PM

Feed refreshes daily · 5:15 a.m. Central

Sources·CISA KEV and NVD (product vendor coverage)

"Most recent entry" is the newest item the upstream feed has published — not our sync time.

Watch items

Recent SonicWall watch items

Showing the 15 most recent items, newest first. Each row links to the official advisory.

15 rows · sorted newest first

Operations view

SonicWall SMA1000 Missing Authorization Vulnerability

critical
activeCISA KEVCVE-2025-40602

SonicWall SMA1000 contains a missing authorization vulnerability that could allow for privilege escalation appliance management console (AMC) of affected devices.

Dec 16, 2025, 6:00 PMOfficial source

SonicWall SMA100 Appliances OS Command Injection Vulnerability

critical
activeCISA KEVCVE-2023-44221

SonicWall SMA100 appliances contain an OS command injection vulnerability in the SSL-VPN management interface that allows a remote, authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user.

Apr 30, 2025, 7:00 PMOfficial source

SonicWall SMA100 Appliances OS Command Injection Vulnerability

critical
activeCISA KEVCVE-2021-20035

SonicWall SMA100 appliances contain an OS command injection vulnerability in the management interface that allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user, which could potentially lead to code execution.

Apr 15, 2025, 7:00 PMOfficial source

SonicWall SonicOS SSLVPN Improper Authentication Vulnerability

critical
activeCISA KEVCVE-2024-53704

SonicWall SonicOS contains an improper authentication vulnerability in the SSLVPN authentication mechanism that allows a remote attacker to bypass authentication. Known ransomware use: Known.

Feb 17, 2025, 6:00 PMOfficial source

SonicWall SMA1000 Appliances Deserialization Vulnerability

critical
activeCISA KEVCVE-2025-23006

SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) contain a deserialization of untrusted data vulnerability, which can enable a remote, unauthenticated attacker to execute arbitrary OS commands. Known ransomware use: Known.

Jan 23, 2025, 6:00 PMOfficial source

SonicWall SonicOS Improper Access Control Vulnerability

critical
activeCISA KEVCVE-2024-40766

SonicWall SonicOS contains an improper access control vulnerability that could lead to unauthorized resource access and, under certain conditions, may cause the firewall to crash. Known ransomware use: Known.

Sep 8, 2024, 7:00 PMOfficial source

SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability

critical
activeCISA KEVCVE-2021-20028

SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection. Known ransomware use: Known.

Mar 27, 2022, 7:00 PMOfficial source

SonicWall SMA100 Directory Traversal Vulnerability

critical
activeCISA KEVCVE-2019-7483

In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server.

Mar 27, 2022, 7:00 PMOfficial source

SonicWall SonicOS Buffer Overflow Vulnerability

critical
activeCISA KEVCVE-2020-5135

A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall.

Mar 14, 2022, 7:00 PMOfficial source

SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability

critical
activeCISA KEVCVE-2021-20038

SonicWall SMA 100 devies are vulnerable to an unauthenticated stack-based buffer overflow vulnerability where exploitation can result in code execution. Known ransomware use: Known.

Jan 27, 2022, 6:00 PMOfficial source

SonicWall Email Security Improper Privilege Management Vulnerability

critical
activeCISA KEVCVE-2021-20021

SonicWall Email Security contains an improper privilege management vulnerability that allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20022 and CVE-2021-20023 to achieve privilege escalation. Known ransomware use: Known.

Nov 2, 2021, 7:00 PMOfficial source

SonicWall SMA100 SQL Injection Vulnerability

critical
activeCISA KEVCVE-2019-7481

SonicWall SMA100 contains a SQL injection vulnerability allowing an unauthenticated user to gain read-only access to unauthorized resources. Known ransomware use: Known.

Nov 2, 2021, 7:00 PMOfficial source

SonicWall SSLVPN SMA100 SQL Injection Vulnerability

critical
activeCISA KEVCVE-2021-20016

SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker. Known ransomware use: Known.

Nov 2, 2021, 7:00 PMOfficial source

SonicWall Email Security Path Traversal Vulnerability

critical
activeCISA KEVCVE-2021-20023

SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation. Known ransomware use: Known.

Nov 2, 2021, 7:00 PMOfficial source

SonicWall Email Security Unrestricted Upload of File Vulnerability

critical
activeCISA KEVCVE-2021-20022

SonicWall Email Security contains an unrestricted upload of file with dangerous type vulnerability that allows a post-authenticated attacker to upload a file to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20023 to achieve privilege escalation. Known ransomware use: Known.

Nov 2, 2021, 7:00 PMOfficial source

Related vendors

Other security vendors in the radar

Vendor watch FAQ

Common questions

What is the SonicWall threat watch page?

It is the SonicWall-specific view inside ITECS Threat Radar, built to track recent advisories, incidents, and watch items that may affect Dallas-area business operations.

How should teams use the SonicWall watch page?

Use it to confirm whether current SonicWall issues overlap with your environment, prioritize remediation, and decide whether you need an assessment, managed security follow-through, or vendor-specific hardening work.

Can ITECS help respond to SonicWall security issues?

Yes. ITECS can help map SonicWall advisories against your systems, validate affected services, prioritize remediation, and connect the issue to broader managed cybersecurity or managed IT workflows.