<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — SonicWall</title><description>Vulnerabilities in SonicWall firewalls, Secure Mobile Access (SMA) appliances, and SSL-VPN gateways — perimeter gear that lands on CISA&apos;s Known Exploited Vulnerabilities catalog with unusual regularity and gets targeted by ransomware crews within days of disclosure. Combined article + CVE feed for the SonicWall beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>CVE-2019-7481 — SonicWall SMA100 SQL Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2019-7481/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-7481/</guid><description>SonicWall SMA100 contains a SQL injection vulnerability allowing an unauthenticated user to gain read-only access to unauthorized resources.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate><category>SonicWall</category><category>high</category><category>cve</category></item><item><title>CVE-2019-7483 — SonicWall SMA100 Directory Traversal Vulnerability</title><link>https://0daynews.com/cve/cve-2019-7483/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-7483/</guid><description>In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate><category>SonicWall</category><category>high</category><category>cve</category></item><item><title>CVE-2020-5135 — SonicWall SonicOS Buffer Overflow Vulnerability</title><link>https://0daynews.com/cve/cve-2020-5135/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-5135/</guid><description>A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate><category>SonicWall</category><category>critical</category><category>cve</category></item><item><title>CVE-2021-20016 — SonicWall SSLVPN SMA100 SQL Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2021-20016/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-20016/</guid><description>SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate><category>SonicWall</category><category>critical</category><category>cve</category></item><item><title>CVE-2021-20021 — SonicWall Email Security Improper Privilege Management Vulnerability</title><link>https://0daynews.com/cve/cve-2021-20021/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-20021/</guid><description>SonicWall Email Security contains an improper privilege management vulnerability that allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20022 and CVE-2021-20023 to achieve privilege escalation.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate><category>SonicWall</category><category>critical</category><category>cve</category></item><item><title>CVE-2021-20022 — SonicWall Email Security Unrestricted Upload of File Vulnerability</title><link>https://0daynews.com/cve/cve-2021-20022/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-20022/</guid><description>SonicWall Email Security contains an unrestricted upload of file with dangerous type vulnerability that allows a post-authenticated attacker to upload a file to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20023 to achieve privilege escalation.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate><category>SonicWall</category><category>high</category><category>cve</category></item><item><title>CVE-2021-20023 — SonicWall Email Security Path Traversal Vulnerability</title><link>https://0daynews.com/cve/cve-2021-20023/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-20023/</guid><description>SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate><category>SonicWall</category><category>medium</category><category>cve</category></item><item><title>CVE-2021-20028 — SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2021-20028/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-20028/</guid><description>SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate><category>SonicWall</category><category>critical</category><category>cve</category></item><item><title>CVE-2021-20035 — SonicWall SMA100 Appliances OS Command Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2021-20035/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-20035/</guid><description>SonicWall SMA100 appliances contain an OS command injection vulnerability in the management interface that allows a remote authenticated attacker to inject arbitrary commands as a &apos;nobody&apos; user, which could potentially lead to code execution.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate><category>SonicWall</category><category>medium</category><category>cve</category></item><item><title>CVE-2021-20038 — SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability</title><link>https://0daynews.com/cve/cve-2021-20038/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-20038/</guid><description>SonicWall SMA 100 devies are vulnerable to an unauthenticated stack-based buffer overflow vulnerability where exploitation can result in code execution.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate><category>SonicWall</category><category>critical</category><category>cve</category></item><item><title>CVE-2023-44221 — SonicWall SMA100 Appliances OS Command Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2023-44221/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-44221/</guid><description>SonicWall SMA100 appliances contain an OS command injection vulnerability in the SSL-VPN management interface that allows a remote, authenticated attacker with administrative privilege to inject arbitrary commands as a &apos;nobody&apos; user.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate><category>SonicWall</category><category>high</category><category>cve</category></item><item><title>CVE-2024-40766 — SonicWall SonicOS Improper Access Control Vulnerability</title><link>https://0daynews.com/cve/cve-2024-40766/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-40766/</guid><description>SonicWall SonicOS contains an improper access control vulnerability that could lead to unauthorized resource access and, under certain conditions, may cause the firewall to crash.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate><category>SonicWall</category><category>critical</category><category>cve</category></item><item><title>CVE-2024-53704 — SonicWall SonicOS SSLVPN Improper Authentication Vulnerability</title><link>https://0daynews.com/cve/cve-2024-53704/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-53704/</guid><description>SonicWall SonicOS contains an improper authentication vulnerability in the SSLVPN authentication mechanism that allows a remote attacker to bypass authentication.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate><category>SonicWall</category><category>critical</category><category>cve</category></item><item><title>CVE-2025-23006 — SonicWall SMA1000 Appliances Deserialization Vulnerability</title><link>https://0daynews.com/cve/cve-2025-23006/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-23006/</guid><description>SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) contain a deserialization of untrusted data vulnerability, which can enable a remote, unauthenticated attacker to execute arbitrary OS commands.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate><category>SonicWall</category><category>critical</category><category>cve</category></item><item><title>CVE-2025-40602 — SonicWall SMA1000 Missing Authorization Vulnerability</title><link>https://0daynews.com/cve/cve-2025-40602/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-40602/</guid><description>SonicWall SMA1000 contains a missing authorization vulnerability that could allow for privilege escalation appliance management console (AMC) of affected devices.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate><category>SonicWall</category><category>medium</category><category>cve</category></item><item><title>CVE-2026-15409 — SonicWall SMA1000 unauthenticated SSRF in Work Place portal</title><link>https://0daynews.com/cve/cve-2026-15409/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-15409/</guid><description>An unauthenticated server-side request forgery in the SonicWall SMA1000 Work Place web interface lets a remote attacker force the appliance to make requests to attacker-chosen destinations. Actively exploited; on CISA KEV.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate><category>SonicWall</category><category>critical</category><category>cve</category></item><item><title>CVE-2026-15410 — SonicWall SMA1000 post-authentication OS command injection</title><link>https://0daynews.com/cve/cve-2026-15410/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-15410/</guid><description>A post-authentication OS command injection in the SonicWall SMA1000 lets an administrator execute arbitrary OS commands on the appliance. Actively exploited alongside CVE-2026-15409; on CISA KEV.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate><category>SonicWall</category><category>high</category><category>cve</category></item><item><title>SonicWall GMS Patched for Critical Unauth RCE Flaws</title><link>https://0daynews.com/articles/2026-08-12-sonicwall-gms-critical-rce-discontinued/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-12-sonicwall-gms-critical-rce-discontinued/</guid><description>Critical unauthenticated RCE and data-read flaws patched in SonicWall GMS, which is end-of-life. If your GMS is internet-reachable, patch or isolate it now.</description><pubDate>Wed, 12 Aug 2026 08:00:00 GMT</pubDate><category>SonicWall</category><category>article</category></item><item><title>CISA: Ransomware Gangs Now Exploiting SonicWall SMA1000</title><link>https://0daynews.com/articles/2026-08-10-sonicwall-sma1000-ransomware-gangs-cisa/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-10-sonicwall-sma1000-ransomware-gangs-cisa/</guid><description>CISA confirmed ransomware operators are actively exploiting CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 in unpatched SonicWall SMA1000 appliances. Patch has been available since July 14.</description><pubDate>Mon, 10 Aug 2026 16:00:00 GMT</pubDate><category>SonicWall</category><category>article</category></item><item><title>Volexity ties SonicWall SMA1000 zero-days to UTA0533</title><link>https://0daynews.com/articles/2026-07-21-volexity-uta0533-sonicwall-sma1000-knuckleball-orangetail-june22/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-21-volexity-uta0533-sonicwall-sma1000-knuckleball-orangetail-june22/</guid><description>Volexity attributes the SonicWall SMA1000 zero-day chain to UTA0533, first observed exploitation on June 22, four custom implants staged after.</description><pubDate>Tue, 21 Jul 2026 04:15:00 GMT</pubDate><category>SonicWall</category><category>article</category></item><item><title>SonicWall SMA1000: Volexity names UTA0533, IoC list out</title><link>https://0daynews.com/articles/2026-07-19-volexity-uta0533-sma1000-rootrun-knuckleball-orangetail/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-19-volexity-uta0533-sma1000-rootrun-knuckleball-orangetail/</guid><description>Volexity attributes the SMA1000 pre-disclosure exploitation to a new actor, UTA0533, active since June 22 — and publishes the toolkit for defenders to hunt.</description><pubDate>Sun, 19 Jul 2026 15:00:00 GMT</pubDate><category>SonicWall</category><category>article</category></item><item><title>SonicWall SMA1000: what Rapid7 saw before disclosure</title><link>https://0daynews.com/articles/2026-07-15-rapid7-sma1000-mdr-writeup-mfa-seeds-dc-pivots/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-15-rapid7-sma1000-mdr-writeup-mfa-seeds-dc-pivots/</guid><description>Rapid7 caught the SMA1000 zero-day exploitation before SonicWall&apos;s advisory. Attackers took credentials, MFA seeds, and pivoted to internal domain controllers.</description><pubDate>Wed, 15 Jul 2026 22:00:00 GMT</pubDate><category>SonicWall</category><category>article</category></item><item><title>SonicWall SMA1000 zero-days on CISA KEV: patch by July 17</title><link>https://0daynews.com/articles/2026-07-14-sonicwall-sma1000-cve-2026-15409-15410-kev-active-exploitation/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-14-sonicwall-sma1000-cve-2026-15409-15410-kev-active-exploitation/</guid><description>Two SMA1000 flaws — a CVSS-10.0 unauthenticated SSRF and a post-auth code injection — hit CISA KEV today. Patch to 12.4.3-03453 or 12.5.0-02835 before July 17.</description><pubDate>Tue, 14 Jul 2026 21:45:00 GMT</pubDate><category>SonicWall</category><category>article</category></item></channel></rss>