Security4 publishersIndependently confirmed2 min readPublished Updated
SonicWall patches a third pre-auth SSRF flaw in SMA 1000 gateways this year
SonicWall patched four flaws in its SMA 1000 VPN gateways, led by CVE-2026-102255, a server-side request forgery open to remote attackers without credentials. The company reports no exploitation, though attackers used two similar SMA 1000 flaws as zero-days this year.
The Watch · Security desk
What happened
- A crafted, unauthenticated request to the internet-facing Work Place portal makes the appliance call internal endpoints that trust it, giving the attacker actions reserved for logged-in users or admins.
- The same release fixes CVE-2026-102256, a post-authentication OS command injection that researcher Benoît Sevens reported along with the SSRF.
- Two Appliance Management Console bugs, path traversal CVE-2026-102257 and cross-site scripting CVE-2026-102258, work only for an attacker already authenticated as administrator.
- Physical and virtual 6210, 7210 and 8200v models are affected, and the fixed hotfixes are 12.4.3-03670 and higher and 12.5.0-03082 and higher.
- SonicWall firewalls and the discontinued, unsupported SMA 100 line are not affected by any of the four flaws.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Anyone who can reach the login page of an unpatched SMA 1000 can drive it, with no credentials stolen or guessed first.
- precedent Attackers exploited two of the three pre-auth SSRFs made public in SMA 1000 this year before fixes existed. Patch planning should start from that record, because the vendor's no-exploitation note covers only the present.
- decision A single firmware upgrade on either supported train closes all four bugs. That leaves operators no triage between them, only the choice of how soon internet-facing gateways get it.
Of the four, CVE-2026-102255 is the only one an attacker can use with nothing more than network access to the portal [5]. The other three need a login, and two of them need an administrator's [7][8]. Help Net Security puts the root cause down to an unintended alternate access path in the Work Place interface [4].
The SSRF's reach could change that ordering. According to Help Net Security, it lets an unauthenticated attacker perform actions normally reserved for logged-in users or admins [5]. The report does not say whether those actions reach the code behind CVE-2026-102256, the command injection fixed in the same release [7]. If they do, the two bugs together would give an attacker with no credentials operating system commands on the gateway [13].
"There is currently no evidence any of the vulnerabilities addressed in this release are being exploited in the wild," SonicWall said [2]. This year's record for this bug class points the other way. Attackers exploited two earlier pre-authentication SSRF flaws in SMA 1000, CVE-2026-15409 and CVE-2026-83548, as zero-days in 2026 [3]. Counting this release, at least three pre-auth SSRFs in the product line have gone public this year, and two of them were exploited before a fix existed [12]. Help Net Security also notes that past reports show both SMA 1000 and SMA 100 appliances are regularly targeted [10].
That makes this a pattern of repeated attacks on one product line. One exploit would have been a one-off. The two earlier zero-days are public record. Whether anyone is already working on CVE-2026-102255 is not known, and SonicWall's statement covers only what the company has seen so far [2].
SMA 1000 boxes are SSL VPN gateways used by medium and large enterprises, managed security service providers and government agencies [11]. They sit at the network edge by design, and the vulnerable Work Place portal is the internet-facing one [5].
What to watch
- Publication of a proof-of-concept or technical write-up for CVE-2026-102255.
- SonicWall revising its advisory to report in-the-wild exploitation of any of the four flaws.
- Any statement from SonicWall or Benoît Sevens on whether the SSRF reaches CVE-2026-102256 without credentials.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence72
- Adoption30
- Hype gap+8
- Incentives
- Insufficient
- Confidence70
Perspective Coverage
4 publishers- Builder
- Builder 23%
- Operator
- Operator 67%
- Investor
- Investor 10%
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
SonicWall patched four vulnerabilities in its Secure Mobile Access (SMA) 1000 series, including CVE-2026-102255, which could allow remote unauthenticated attackers "to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations."
ReportedSupportedSource: Help Net Security, quoting SonicWall4 sources— create a free account to open themView cited source - [2]
"There is currently no evidence any of the vulnerabilities addressed in this release are being exploited in the wild,"
ReportedSupportedSource: SonicWall, as quoted by Help Net Security4 sources— create a free account to open themView cited source - [3]
In 2026, two pre-authentication server-side request forgery flaws (CVE-2026-15409, CVE-2026-83548) in SonicWall's SMA 1000 appliances have been leveraged as zero-days.
ReportedSupportedSource: Help Net Security4 sources— create a free account to open themView cited source - [4]
CVE-2026-102255 is a pre-authentication SSRF vulnerability in the SMA 1000 Appliance Work Place interface, due to an unintended alternate access path.
ReportedSupportedSource: Help Net Security4 sources— create a free account to open themView cited source - [5]
An unauthenticated attacker could send a crafted request to the internet-facing Work Place portal, pushing the appliance to make requests to internal endpoints that trust it, allowing the attacker to perform actions normally reserved for logged-in users or admins.
ReportedSupportedSource: Help Net Security4 sources— create a free account to open themView cited source - [6]
SonicWall's firewall products and the discontinued and unsupported SMA 100 Series are not affected.
ReportedSupportedSource: Help Net Security4 sources— create a free account to open themView cited source - [7]
CVE-2026-102256 is a post-authentication OS command injection flaw; it and CVE-2026-102255 were reported by Benoît Sevens.
ReportedSupportedSource: Help Net Security3 sources— create a free account to open themView cited source - [8]
CVE-2026-102257 (path traversal) and CVE-2026-102258 (cross-site scripting) in the Appliance Management Console are exploitable only if the attacker is authenticated as administrator; they were reported by researcher Brian Mariani.
ReportedSupportedSource: Help Net Security3 sources— create a free account to open themView cited source - [9]
The vulnerabilities affect physical and virtual SMA 1000 models 6210, 7210 and 8200v. SonicWall fixed all four and advised upgrading to firmware hotfixes 12.4.3-03670 and higher, and 12.5.0-03082 and higher.
ReportedSupportedSource: Help Net Security, citing SonicWall3 sources— create a free account to open themView cited source - [10]
Past reports have shown that SonicWall's SMA appliances, both the 1000 and 100 series, are regularly targeted by attackers.
ReportedSupportedSource: Help Net Security2 sources— create a free account to open themView cited source - [11]
The SonicWall SMA 1000 series is a line of SSL VPN gateways used by medium to large enterprises, managed security service providers, and government agencies.
ReportedSupportedSource: Help Net Security2 sources— create a free account to open themView cited source - [12]
At least three pre-authentication SSRF flaws in SMA 1000 appliances have been made public in 2026, and two of them were exploited as zero-days.
- [13]
If the SSRF's access to actions reserved for logged-in users or admins reaches the code path behind CVE-2026-102256, the two flaws together would give an unauthenticated attacker OS command execution on the gateway.
Sources
4 independent publishers whose own reporting we read for this story.
- bleepingcomputer.comSonicWall warns of max severity SSRF flaw in SMA1000 gateways
1 article · October 7, 2026
- helpnetsecurity.comSonicWall fixes pre-auth SSRF flaw in SMA 1000 appliances (CVE-2026-102255)
1 article · October 7, 2026
- securityaffairs.comSonicWall Fixes Max Severity Pre-Auth Flaw in SMA1000 Appliances
1 article · October 7, 2026
- thehackernews.comSonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances
2 articles · October 8, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- VPN gateway vulnerabilitiesFollow
- Server-Side Request ForgeryFollow
- Zero-Day ExploitationFollow