DKDKCISSPSearch
Cloud & IdentityDEVELOPING

SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

SonicWall has released hotfixes for four flaws in its SMA1000 appliances, the gateways that give remote workers access to a company's network and applications.

DKCISSP News DeskThe Hacker News7 Oct 2026, 9:47 pm
SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances
Image courtesy of The Hacker News. Original report
DKCISSP REPORT

SonicWall has released hotfixes for four flaws in its SMA1000 appliances, the gateways that give remote workers access to a company's network and applications.

The most serious could allow an attacker without a login to send requests through the appliance and reach internal functions.

SonicWall rates it 10.0 on the CVSS scale and says it has no evidence that any of the four flaws is being used in attacks.

All four flaws affect SMA1000 models 6210, 7210 and 8200v on these platform-hotfix versions: The affected versions include 12.4.3-03526 and 12.5.0-02952, which SonicWall named on September 1 as the fix for two flaws it reported as exploited.

An appliance still on those versions needs the new hotfix.

SonicWall disclosed CVE-2026-15409 and CVE-2026-15410 on July 14, and CVE-2026-83548 and CVE-2026-83549 on September 1.

The most serious flaw, tracked as CVE-2026-102255 , is a server-side request forgery (SSRF) bug in WorkPlace, the portal that SMA1000 users log in to.

SSL-VPN on SonicWall firewalls and the SMA 100 Series are not affected.

It exists due to an unintended access path through SonicWall and can be reached before authentication.

An attacker who abuses that path could SonicWall said in its security advisory , dated October 6, without saying which functions.

Both times, it said it had investigated attacks exploiting the flaws: in July and in September.

Each pair consisted of an SSRF flaw that required no login and a second flaw that could allow a logged-in administrator to run commands on the appliance.

SonicWall credited outside researchers for the four new flaws: Benoît Sevens of Anthropic for CVE-2026-102255 and CVE-2026-102256, and Brian Mariani of DigitalCanion SA for the other two, one of them reported through Trend Micro's Zero Day Initiative.

The hotfix is available from the MySonicWall portal, and the appliance restarts when the installation finishes.

What happened

SonicWall has released hotfixes for four flaws in its SMA1000 appliances, the gateways that give remote workers access to a company's network and applications.

The most serious could allow an attacker without a login to send requests through the appliance and reach internal functions.

SonicWall rates it 10.0 on the CVSS scale and says it has no evidence that any of the four flaws is being used in attacks.

What changed

All four flaws affect SMA1000 models 6210, 7210 and 8200v on these platform-hotfix versions: The affected versions include 12.4.3-03526 and 12.5.0-02952, which SonicWall named on September 1 as the fix for two flaws it reported as exploited.

An appliance still on those versions needs the new hotfix.

SonicWall disclosed CVE-2026-15409 and CVE-2026-15410 on July 14, and CVE-2026-83548 and CVE-2026-83549 on September 1.

Who is affected

The most serious flaw, tracked as CVE-2026-102255 , is a server-side request forgery (SSRF) bug in WorkPlace, the portal that SMA1000 users log in to.

SSL-VPN on SonicWall firewalls and the SMA 100 Series are not affected.

Why it matters

It exists due to an unintended access path through SonicWall and can be reached before authentication.

An attacker who abuses that path could SonicWall said in its security advisory , dated October 6, without saying which functions.

Technical details

Both times, it said it had investigated attacks exploiting the flaws: in July and in September.

Each pair consisted of an SSRF flaw that required no login and a second flaw that could allow a logged-in administrator to run commands on the appliance.

SonicWall credited outside researchers for the four new flaws: Benoît Sevens of Anthropic for CVE-2026-102255 and CVE-2026-102256, and Brian Mariani of DigitalCanion SA for the other two, one of them reported through Trend Micro's Zero Day Initiative.

Response

The hotfix is available from the MySonicWall portal, and the appliance restarts when the installation finishes.

It is the third time this year that SonicWall has fixed a 10.0-rated SSRF flaw in WorkPlace that needs no login.

What security teams should do

In its July and September advisories, SonicWall told customers to check their appliances for indicators of compromise and, if any were found, to re-image or redeploy the appliance, change user and administrator passwords, and reset the TOTP tokens used for one-time login codes.

While it has not yet flagged these flaws as actively exploited, the company urged customers to deploy hotfixes released on Tuesday to block potential attacks targeting their virtual or physical appliances.

What remains unknown

SonicWall has not said whether the new SSRF flaw can be combined with the other three in the same way.

Attribution

The Hacker News: SonicWall has released hotfixes for four flaws in its SMA1000 appliances, the gateways that give remote workers access to a company's network and applications.

BleepingComputer: SonicWall has released hotfixes to address a maximum-severity server-side request forgery (SSRF) flaw in SMA1000 series appliances.

Help Net Security: SonicWall has patched four vulnerabilities in its popular Secure Mobile Access (SMA) 1000 series of appliances, including one (CVE-2026-102255) that could allow remote unauthenticated attackers “to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations.” “There is currently no evidence any of the vulnerabilities addressed in this release are being exploited in the wild,” the vendor said , but the one mentioned above could soon be, given attackers’ track record with similar flaws.

What to watch next

Watch for additional victim details, indicators of compromise and follow-on exploitation reports.

Watch for revised vendor guidance, fixed versions and mitigation updates.

MORE IN CLOUD & IDENTITY

More cybersecurity reporting

LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro WarningsThe Hacker News · 6 Oct 2026, 5:27 pmHacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic StealerThe Hacker News · 26 Sept 2026, 11:53 pm