Known exploited / historically exploited security risk
CVE-2021-20021 — SonicWall Email Security
A SonicWall Email Security vulnerability affecting version 10.0.9.x that can allow pre-authentication administrative account creation. CISA included it among routinely exploited vulnerabilities.
Business relevance
If SonicWall Email Security is present in your environment, confirm whether the installed version and configuration are affected. The existence of this CVE does not by itself prove that a specific system is vulnerable or compromised.
What to check
- Identify SonicWall Email Security deployments.
- Confirm the exact installed version.
- Verify vendor-supported remediation.
- Review administrative accounts and relevant logs where applicable.
Source record
Authoritative source: CISA routinely exploited vulnerabilities advisory.
CompFlorida record reviewed: September 21, 2026.
Vendor: SonicWall
Product: SonicWall Email Security
CVE: CVE-2021-20021
Need help checking applicability?
CompFlorida can help identify the product/version in use, review exposure and coordinate the appropriate remediation path.
Request a Technology Risk Review
