SonicWall’s latest critical flaw indicates a security pattern, not another one-off bug
SonicWall disclosed a CVSS 10 pre-auth SSRF in SMA1000, with no confirmed exploitation yet.
SonicWall disclosed CVE-2026-102255, a CVSS 10 pre-authentication SSRF in the SMA1000 Work Place interface on models 6210, 7210, and 8200v running 12.4.3-03526 and 12.5.0-02952 and earlier. It also disclosed CVE-2026-102256 (CVSS 7.8), CVE-2026-102257 (7.2), and CVE-2026-102258 (5.5). SonicWall said there is no evidence the critical flaw is exploited and advised upgrades to 12.4.3-03670 or 12.5.0-03082, which are the only fixes. Earlier SMA1000 bugs, including CVE-2026-83548, CVE-2026-83549, and zero-day CVE-2026-15409, were actively exploited, and CISA has listed 19 SonicWall flaws as exploited over four years.