Exploited CVEs / By vendor / SonicWall

SonicWall vulnerabilities actively exploited

17 SonicWall CVEs on the CISA Known Exploited Vulnerabilities catalog, newest first. Refreshed daily.

Every CVE below is confirmed exploited in the wild, not just theoretically severe. The newest addition is CVE-2026-15409 (SMA1000 Appliances, added 2026-07-14). 10 of the 17 are used in ransomware campaigns. New CISA KEV entries appear here the day they are cataloged; the freshest across all vendors are on exploited this week.

17 exploited CVEs10 ransomware-linked

Senserva AI Opinion and rich prompt for SonicWall exploited CVEs

Copy this prompt into Claude, ChatGPT, or Copilot. The facts are included, sourced from this page.

SMA1000 Appliances: 3 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2026-15409SMA1000 Appliances2026-07-14CVSS 10.0, EPSS 78%
CVE-2026-15410SMA1000 Appliances2026-07-14CVSS 7.2, EPSS 76%
CVE-2025-23006SMA1000 Appliances2025-01-24ransomware, CVSS 9.8, EPSS 23%

SonicOS: 3 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2024-53704SonicOS2025-02-18ransomware, CVSS 9.8, EPSS 95%
CVE-2024-40766SonicOS2024-09-09ransomware, CVSS 9.8, EPSS 18%
CVE-2020-5135SonicOS2022-03-15CVSS 9.8, EPSS 25%

SonicWall Email Security: 3 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2021-20021SonicWall Email Security2021-11-03ransomware, CVSS 9.8, EPSS 83%
CVE-2021-20022SonicWall Email Security2021-11-03ransomware, CVSS 7.2, EPSS 17%
CVE-2021-20023SonicWall Email Security2021-11-03ransomware, CVSS 4.9, EPSS 50%

Other SonicWall products

CVEProductAdded to KEVSignals
CVE-2025-40602SMA1000 appliance2025-12-17CVSS 6.6, EPSS 2%
CVE-2023-44221SMA100 Appliances2025-05-01CVSS 7.2, EPSS 75%
CVE-2021-20035SMA100 Appliances2025-04-16CVSS 6.5, EPSS 4%
CVE-2019-7483SMA1002022-03-28CVSS 7.5, EPSS 4%
CVE-2021-20028Secure Remote Access (SRA)2022-03-28ransomware, CVSS 9.8, EPSS 30%
CVE-2021-20038SMA 100 Appliances2022-01-28ransomware, CVSS 9.8, EPSS 100%
CVE-2019-7481SMA1002021-11-03ransomware, CVSS 7.5, EPSS 100%
CVE-2021-20016SSLVPN SMA1002021-11-03ransomware, CVSS 9.8, EPSS 37%

Common questions about exploited SonicWall CVEs

Which SonicWall vulnerabilities are actively exploited?

As of July 2026, 17 SonicWall CVEs are on the CISA Known Exploited Vulnerabilities catalog, meaning exploitation in the wild is confirmed. The most-listed products are SMA1000 Appliances (3), SonicOS (3), SonicWall Email Security (3). 10 are linked to ransomware campaigns.

What is the newest exploited SonicWall CVE?

CVE-2026-15409, affecting SMA1000 Appliances, added to the CISA KEV catalog on 2026-07-14. This page refreshes daily, so the newest entry is always first in the table.

How urgent are these SonicWall CVEs?

KEV listing is the strongest fix-first signal there is: it means confirmed exploitation, not a prediction. Patch these ahead of higher-CVSS issues that nobody is exploiting. Check the vendor advisory (linked below) for fixed versions and workarounds.

Can I ask my own AI about exploited SonicWall CVEs?

Yes. This page includes a free copy-paste AI prompt carrying the newest SonicWall KEV entries, with CVSS, EPSS, and ransomware context, into Claude, ChatGPT, or Copilot. The data is refreshed twice a day (5 AM and 3 PM US Central).

All vendors, searchable with due dates and CSV export: the exploited-CVE tracker. Every vendor with a page: exploited by vendor.

SenservaThree Free Unlimited Audits of your Microsoft 365, Intune, Defender, and Entra ID, with full Claude MCP support. 1 scan to find, 2 to review your fixes.Start my Audit
Lexicon: the terms on this page
CVE
Common Vulnerabilities and Exposures. A unique ID for one publicly known vulnerability, such as CVE-2025-1234.
KB
Microsoft Knowledge Base article. The identifier for a specific Microsoft update.
KEV
CISA Known Exploited Vulnerabilities. CVEs confirmed exploited in the wild. Fix these first.
CVSS
Common Vulnerability Scoring System. A standardized Severity score from 0 to 10.
EPSS
Exploit Prediction Scoring System. The probability a CVE will be exploited in the next 30 days.
MSRC
Microsoft Security Response Center. Microsoft's Patch Tuesday advisories and KB-to-CVE mapping.
NVD
National Vulnerability Database (NIST). Authoritative CVE metadata and CVSS scores.
Ransomware
The vulnerability is linked to known ransomware activity.
Reference: Microsoft CVE and vulnerability management, the full CVE-to-patch lookup ranked by real-world risk, and the Microsoft patching guide, how Intune, Windows Autopatch, Defender, and Azure Update Manager fit together.
Data notice: this page, the feeds, and the API are provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data (MSRC, NVD, CISA KEV, EPSS) and accepts no liability for actions taken based on it; verify against the authoritative vendor advisory before acting. Built daily with Senserva Trustworthy AI. All use of this data is subject to the Senserva EULA.