SonicWall Patches 4 SMA1000 Flaws, Including Critical Pre-Auth SSRF Rated CVSS 10
SonicWall patched four SMA 1000 flaws, including an unauthenticated SSRF rated CVSS 10.0.
SonicWall advisory SNWLID-2026-0017, published October 6, 2026, patches four flaws in SMA 1000 Series appliances, including physical and virtual SMA 6210, 7210, and 8200v. CVE-2026-102255 is a pre-authentication SSRF (CVSS 10.0) in the WorkPlace interface that can make the device act as an unintended forward proxy. CVE-2026-102256 is authenticated command injection scored 7.8, CVE-2026-102257 is a Zip Slip issue in the management console scored 7.2 that can lead to remote code execution, and CVE-2026-102258 is stored XSS scored 5.5. SonicWall says it has no evidence of exploitation and no workaround; builds 12.4.3-03526 and earlier and 12.5.0-02952 and earlier need 12.4.3-03670 or 12.5.0-03082. SMA 100 Series and firewall SSL-VPN are unaffected, and September fixes for CVE-2026-83548 and CVE-2026-83549 do not resolve these bugs.
- CVE-2026-102255 is pre-auth SSRF, CVSS 10.0, via an unintended proxy path.
- Also fixed: command injection 7.8, Zip Slip 7.2, and stored XSS 5.5.
- SonicWall reports no evidence these four flaws are exploited; no workaround exists.
- Upgrade to 12.4.3-03670 or 12.5.0-03082; September patches do not cover them.
- SMA 100 Series and firewall SSL-VPN products are not affected.
Vulnerabilities mentionedAll →
- CVE-2026-10225510.0—Pre-auth SSRF in SonicWall SMA1000 Work Place interfacepublished · SonicWall SMA1000 Appliance (Work Place interface)+1 related
- CVE-2026-1022567.8—Authenticated OS command injection in SonicWall SMA1000published · SonicWall SMA1000
Full article615 words · extracted from cybersecuritynews.com · click to collapse
SonicWall has patched four vulnerabilities in its Secure Mobile Access (SMA) 1000 Series appliances, including a critical server-side request forgery (SSRF) flaw with a maximum CVSS score of 10.0.
The bug could let a remote attacker without valid credentials make the appliance send requests on their behalf, reach internal functions, and perform unauthorized operations.
The company published security advisory SNWLID-2026-0017 on October 6, 2026. SonicWall said it currently has no evidence that any of these four vulnerabilities are being exploited in the wild. However, it strongly advises affected customers to install the fixed software releases. The updates cover physical and virtual SMA 6210, SMA 7210, and SMA 8200v appliances.
Critical Pre-Authentication SSRF
Tracked as CVE-2026-102255, the most serious flaw affects the SMA1000 Appliance WorkPlace interface. It stems from an unintended alternate access path that allows the device to act as a forward proxy.
An attacker could abuse this path to make requests through the appliance rather than connect directly to protected internal functions.
This makes the issue especially concerning because the attacker does not need to sign in or persuade a user to take action. Its CVSS vector describes a network-accessible attack with low complexity and potentially high impact on confidentiality, integrity, and availability. SonicWall classifies it under CWE-918 for SSRF and CWE-441 for an unintended proxy, also called a confused deputy.
Additional Security Flaws
CVE-2026-102256 is a post-authentication command-injection vulnerability rated 7.8. Under specific conditions, an authenticated administrator could execute arbitrary operating-system commands, resulting in remote code execution. The advisory does not establish that this flaw can be chained with the critical SSRF issue.
CVE-2026-102257, rated 7.2, is a Zip Slip vulnerability in the Appliance Management Console (AMC). A specially crafted archive could cause files to be extracted outside the intended destination folder. SonicWall says this path-traversal issue can lead to remote code execution.
The fourth flaw, CVE-2026-102258, is stored cross-site scripting in AMC, with a CVSS score of 5.5. An authenticated administrator could, under specific conditions, store and potentially execute arbitrary JavaScript in the management console.
SonicWall credited Benoît Sevens of Anthropic with reporting the SSRF and command-injection flaws. Brian Mariani reported the Zip Slip issue through Trend Micro’s Zero Day Initiative, tracked as ZDI-CAN-28924, and received credit through DigitalCanion SA for the stored XSS vulnerability.
Affected Versions And Required Updates
Affected releases are 12.4.3-03526 and earlier, and 12.5.0-02952 and earlier. Customers should upgrade to platform-hotfix 12.4.3-03670 or later, or 12.5.0-03082 or later, depending on their software branch. SonicWall provides the latest hotfix through MySonicWall and lists no workaround for these vulnerabilities. The current fixes address all four issues across both affected firmware branches.
SSL-VPN services running on SonicWall firewalls and the SMA 100 Series product line are not affected. This distinction helps administrators identify the correct devices without treating every SonicWall VPN deployment as vulnerable to this advisory.
Cyber Security News previously covered separate SMA1000 vulnerabilities, CVE-2026-83548 and CVE-2026-83549, that SonicWall reported as actively exploited in September.
Those earlier fixes were 12.4.3-03526 and 12.5.0-02952, which are now listed as affected by this new advisory. Installing September’s update therefore does not resolve October’s newly disclosed flaws. Teams should check each appliance’s installed build against the latest fixed versions and complete the required upgrade, rather than rely on an earlier patch as proof that the device remains protected.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.