SonicWall warns of max severity SSRF flaw in SMA1000 gateways
SonicWall patches maximum-severity unauthenticated SSRF CVE-2026-102255 in SMA1000 gateways; no exploitation reported.
SonicWall released hotfixes for CVE-2026-102255, a maximum-severity server-side request forgery flaw in the WorkPlace interface of SMA1000 models 6210, 7210, and 8200v. A remote unauthenticated attacker could make the appliance issue requests and reach internal functionality; the SMA 100 Series and firewall SSL-VPN are unaffected. SonicWall said there is no evidence this flaw is being exploited in the wild. Shadowserver tracks more than 400 internet-exposed SMA1000 appliances, and prior SMA1000 zero-days, including CVE-2026-15409 and CVE-2026-15410, were previously used in ransomware-linked attacks.