DKDKCISSPSearch
PolicyDEVELOPING

SonicWall warns of max severity SSRF flaw in SMA1000 gateways

SonicWall has released hotfixes to address a maximum-severity server-side request forgery (SSRF) flaw in SMA1000 series appliances.

DKCISSP News DeskBleepingComputer7 Oct 2026, 5:07 pm
SonicWall warns of max severity SSRF flaw in SMA1000 gateways
Image courtesy of BleepingComputer. Original report
DKCISSP REPORT

Tracked as CVE-2026-102255 , the vulnerability was found in the Appliance WorkPlace interface of SMA1000 6210, 7210, and 8200v models, but it does not affect the SMA 100 Series product line or SSL-VPN running on SonicWall firewalls.

SonicWall has released hotfixes to address a maximum-severity server-side request forgery (SSRF) flaw in SMA1000 series appliances.

SonicWall has patched four vulnerabilities in its popular Secure Mobile Access (SMA) 1000 series of appliances, including one (CVE-2026-102255) that could allow remote unauthenticated attackers “to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations.” “There is currently no evidence any of the vulnerabilities addressed in this release are being exploited in the wild,” the vendor said , but the one mentioned above could soon be, given attackers’ track record with similar flaws.

Although CVE-2026-102255 is not exploited in the wild, attackers often target SMA1000 flaws because they affect enterprise-grade secure remote access gateways used by government agencies, Managed Service Providers (MSSPs), and many large corporations to provide VPN access to internal apps and corporate networks.

In 2026, two pre-authentication server-side request forgery flaws ( CVE-2026-15409 , CVE-2026-83548 ) in SonicWall’s SMA 1000 appliances have been leveraged as zero-days.

Last month, SonicWall also warned customers that attackers were chaining two new zero-days (CVE-2026-83548 and CVE-2026-83549) to execute remote code on vulnerable SMA1000 gateways.

CVE-2026-102255 is a pre-authentication SSRF vulnerability in the SMA 1000 Appliance Work Place interface, due to an unintended alternate access path.

In July, two SMA1000 zero-days (CVE-2026-15409 and CVE-2026-15410) were exploited for weeks to install custom Sou5, OrangeTail, and RootRun malware on vulnerable VPN appliances in attacks that the U.S.

The flaw stems from an unintended alternate access-path weakness that remote attackers without privileges can exploit in low-complexity attacks .

While it has not yet flagged these flaws as actively exploited, the company urged customers to deploy hotfixes released on Tuesday to block potential attacks targeting their virtual or physical appliances.

What happened

Tracked as CVE-2026-102255 , the vulnerability was found in the Appliance WorkPlace interface of SMA1000 6210, 7210, and 8200v models, but it does not affect the SMA 100 Series product line or SSL-VPN running on SonicWall firewalls.

SonicWall has released hotfixes to address a maximum-severity server-side request forgery (SSRF) flaw in SMA1000 series appliances.

What changed

SonicWall has patched four vulnerabilities in its popular Secure Mobile Access (SMA) 1000 series of appliances, including one (CVE-2026-102255) that could allow remote unauthenticated attackers “to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations.” “There is currently no evidence any of the vulnerabilities addressed in this release are being exploited in the wild,” the vendor said , but the one mentioned above could soon be, given attackers’ track record with similar flaws.

Although CVE-2026-102255 is not exploited in the wild, attackers often target SMA1000 flaws because they affect enterprise-grade secure remote access gateways used by government agencies, Managed Service Providers (MSSPs), and many large corporations to provide VPN access to internal apps and corporate networks.

Who is affected

In 2026, two pre-authentication server-side request forgery flaws ( CVE-2026-15409 , CVE-2026-83548 ) in SonicWall’s SMA 1000 appliances have been leveraged as zero-days.

Last month, SonicWall also warned customers that attackers were chaining two new zero-days (CVE-2026-83548 and CVE-2026-83549) to execute remote code on vulnerable SMA1000 gateways.

Why it matters

CVE-2026-102255 is a pre-authentication SSRF vulnerability in the SMA 1000 Appliance Work Place interface, due to an unintended alternate access path.

In July, two SMA1000 zero-days (CVE-2026-15409 and CVE-2026-15410) were exploited for weeks to install custom Sou5, OrangeTail, and RootRun malware on vulnerable VPN appliances in attacks that the U.S.

Technical details

The flaw stems from an unintended alternate access-path weakness that remote attackers without privileges can exploit in low-complexity attacks .

While it has not yet flagged these flaws as actively exploited, the company urged customers to deploy hotfixes released on Tuesday to block potential attacks targeting their virtual or physical appliances.

CISA has added 19 SonicWall vulnerabilities to its list of actively exploited flaws over the last four years, 13 of which have also been abused in ransomware attacks.

Response

SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

What security teams should do

SonicWall has fixed all four and advised customers to upgrade to the following firmware versions (hotfixes): 12.4.3-03670 and higher, and 12.5.0-03082 and higher.

Attribution

BleepingComputer: SonicWall has released hotfixes to address a maximum-severity server-side request forgery (SSRF) flaw in SMA1000 series appliances.

Help Net Security: SonicWall has patched four vulnerabilities in its popular Secure Mobile Access (SMA) 1000 series of appliances, including one (CVE-2026-102255) that could allow remote unauthenticated attackers “to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations.” “There is currently no evidence any of the vulnerabilities addressed in this release are being exploited in the wild,” the vendor said , but the one mentioned above could soon be, given attackers’ track record with similar flaws.

What to watch next

Watch for new exploitation reports and updated indicators of compromise.

Watch for updated vendor guidance and fixed-version details.

MORE IN POLICY

More cybersecurity reporting

Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' MailboxesThe Hacker News · 5 Oct 2026, 9:51 pmMore UK Schools Are Recovering Faster from Cyber IncidentsInfosecurity Magazine · 5 Oct 2026, 3:00 pmCritical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host FilesThe Hacker News · 17 Sept 2026, 9:07 pmCritical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS ZoneThe Hacker News · 17 Sept 2026, 6:00 pm