SonicWall patches CVSS 10 SMA 1000 SSRF; Splunk fixes bugs
SonicWall patched CVSS 10 pre-auth SSRF CVE-2026-102255 and three other SMA 1000 flaws, with no known exploitation; Splunk also fixed critical bugs.
SonicWall advisory SNWLID-2026-0017, published October 6, 2026, patches four flaws in SMA 1000 physical and virtual models 6210, 7210, and 8200v. CVE-2026-102255 is a pre-authentication SSRF in the WorkPlace interface, rated CVSS 10.0 and maximum severity, that could let a remote unauthenticated attacker request internal endpoints, reach internal functionality, or use the appliance as an unintended forward proxy. Companion issues are authenticated OS command injection CVE-2026-102256 (CVSS 7.8) and stored or administrator-only XSS CVE-2026-102258 (CVSS 5.5); sources disagree on CVE-2026-102257, which Help Net Security calls administrator-only path traversal while Cyber Security News and Security Affairs describe a management-console Zip Slip scored 7.2 that can lead to remote code execution. SonicWall reports no known exploitation and no workaround and advises 12.4.3-03670 or 12.5.0-03082 and later for 12.4.3-03526 and 12.5.0-02952 and older, but Canadian Centre for Cyber Security advisory AV26-1017 lists those hotfix versions and earlier as still impacted and cites no CVEs. The SMA 100 series is unaffected, and firewall SSL-VPN products are unaffected according to BleepingComputer, Cyber Security News, and Security Affairs, while Help Net Security says firewalls are unaffected; Shadowserver tracks more than 400 internet-exposed SMA1000 appliances, prior zero-days CVE-2026-15409 and CVE-2026-15410 were linked to ransomware attacks, and September fixes for CVE-2026-83548 and CVE-2026-83549 do not resolve the new bugs. SecurityWeek on October 8 also reported that Splunk fixed dozens of bugs in Splunk Enterprise, MCP Server, and the Add-on for Amazon Web Services, including three critical Enterprise flaws enabling command execution, unauthorized access, and code injection, plus an MCP Server patch stopping authenticated users from redirecting API requests to attacker URLs.
- CVE-2026-102255 is a pre-authentication SSRF in the SMA 1000 WorkPlace interface on models 6210, 7210, and 8200v, rated CVSS 10.0.
- Also patched: authenticated command injection CVE-2026-102256 (CVSS 7.8) and XSS CVE-2026-102258 (CVSS 5.5); sources disagree on CVE-2026-102257 (admin path traversal vs. Zip Slip, CVSS 7.2, possible RCE).
- Vendor fixes are 12.4.3-03670 or 12.5.0-03082 and later; Canada’s AV26-1017 (Oct. 7, 2026) lists those builds and earlier as affected and names no CVEs.
- SonicWall reports no known exploitation and no workaround; SMA 100 series and firewall SSL-VPN products are unaffected.
Coverage timelineoldest first · each row is one article
- · 1d agoSonicWall fixes pre-auth SSRF flaw in SMA 1000 appliances (CVE-2026-102255)
Help Net Security· 70
SonicWall patched pre-auth SSRF CVE-2026-102255 in SMA 1000 appliances, with no known exploitation.
- · 1d agoSonicWall warns of max severity SSRF flaw in SMA1000 gateways
BleepingComputer· 76
SonicWall patches maximum-severity unauthenticated SSRF CVE-2026-102255 in SMA1000 gateways; no exploitation reported.
- · 1d agoSonicWall Patches 4 SMA1000 Flaws, Including Critical Pre-Auth SSRF Rated CVSS 10
Cyber Security News· 68
Vulnerabilities in this storyAll →
- CVE-2026-10225510.0—Pre-auth SSRF in SonicWall SMA1000 Work Place interfacepublished · SonicWall SMA1000 Appliance (Work Place interface)+1 related
- CVE-2026-1022567.8—Authenticated OS command injection in SonicWall SMA1000published · SonicWall SMA1000