SonicWall fixes pre-auth SSRF flaw in SMA 1000 appliances (CVE-2026-102255)
SonicWall patched pre-auth SSRF CVE-2026-102255 in SMA 1000 appliances, with no known exploitation.
SonicWall patched four vulnerabilities in SMA 1000 SSL VPN appliances, models 6210, 7210, and 8200v. CVE-2026-102255 is a pre-authentication SSRF in the Work Place interface that could let remote attackers make the appliance request internal endpoints and perform unauthorized operations. CVE-2026-102256 is a post-authentication OS command injection, while CVE-2026-102257 and CVE-2026-102258 are administrator-only path traversal and cross-site scripting flaws. SonicWall says none of these four are known to be exploited and advises firmware 12.4.3-03670 or 12.5.0-03082 and later; firewalls and the SMA 100 series are unaffected.
- CVE-2026-102255 is unauthenticated SSRF on the Work Place portal.
- Three companion flaws require authentication, two of them administrator access.
- Fixed in hotfixes 12.4.3-03670 and 12.5.0-03082 and later.
- Vendor reports no evidence these four flaws are exploited.
- Earlier SMA 1000 pre-auth SSRF bugs were used as zero-days.
Vulnerabilities mentionedAll →
- CVE-2026-10225510.0—Pre-auth SSRF in SonicWall SMA1000 Work Place interfacepublished · SonicWall SMA1000 Appliance (Work Place interface)+1 related
- CVE-2026-1022567.8—Authenticated OS command injection in SonicWall SMA1000published · SonicWall SMA1000
Full article336 words · extracted from helpnetsecurity.com · click to collapse
SonicWall has patched four vulnerabilities in its popular Secure Mobile Access (SMA) 1000 series of appliances, including one (CVE-2026-102255) that could allow remote unauthenticated attackers “to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations.”
“There is currently no evidence any of the vulnerabilities addressed in this release are being exploited in the wild,” the vendor said, but the one mentioned above could soon be, given attackers’ track record with similar flaws.
Past reports have shown that SonicWall’s SMA appliances – both the 1000 and 100 series – are regularly targeted by attackers.
In 2026, two pre-authentication server-side request forgery flaws (CVE-2026-15409, CVE-2026-83548) in SonicWall’s SMA 1000 appliances have been leveraged as zero-days.
Vulnerability details and fixes
The SonicWall SMA 1000 series is a line of SSL VPN gateways used by medium to large enterprises, managed security service providers, and government agencies.
CVE-2026-102255 is a pre-authentication SSRF vulnerability in the SMA 1000 Appliance Work Place interface, due to an unintended alternate access path.
An unauthenticated attacker could send a crafted request to this internet-facing portal, pushing the appliance to make requests to internal endpoints that trust it, allowing the attacker to perform actions normally reserved for logged-in users or admins.
CVE-2026-102255 and CVE-2026-102256, a post-authentication OS command injection flaw, were reported by Benoît Sevens.
CVE-2026-102257 and CVE-2026-102258 – a path traversal and a cross-site scripting flaw in the appliances’ Appliance Management Console, respectively – are exploitable only if the attacker is authenticated as administrator. These were reported by researcher Brian Mariani.
The vulnerabilities affect physical and virtual SMA 1000 models: 6210, 7210, and 8200v.
SonicWall has fixed all four and advised customers to upgrade to the following firmware versions (hotfixes): 12.4.3-03670 and higher, and 12.5.0-03082 and higher.
SonicWall’s firewall products and the (discontinued and unsupported) SMA 100 Series product line are not affected.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!
