Skip to content

Security4 publishersIndependently confirmed2 min readPublished Updated

SonicWall patches a third pre-auth SSRF flaw in SMA 1000 gateways this year

SonicWall patched four flaws in its SMA 1000 VPN gateways, led by CVE-2026-102255, a server-side request forgery open to remote attackers without credentials. The company reports no exploitation, though attackers used two similar SMA 1000 flaws as zero-days this year.

The Watch · Security desk

How we use AISend a correction

What happened

  • A crafted, unauthenticated request to the internet-facing Work Place portal makes the appliance call internal endpoints that trust it, giving the attacker actions reserved for logged-in users or admins.
  • The same release fixes CVE-2026-102256, a post-authentication OS command injection that researcher Benoît Sevens reported along with the SSRF.
  • Two Appliance Management Console bugs, path traversal CVE-2026-102257 and cross-site scripting CVE-2026-102258, work only for an attacker already authenticated as administrator.
  • Physical and virtual 6210, 7210 and 8200v models are affected, and the fixed hotfixes are 12.4.3-03670 and higher and 12.5.0-03082 and higher.
  • SonicWall firewalls and the discontinued, unsupported SMA 100 line are not affected by any of the four flaws.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Anyone who can reach the login page of an unpatched SMA 1000 can drive it, with no credentials stolen or guessed first.
  • precedent Attackers exploited two of the three pre-auth SSRFs made public in SMA 1000 this year before fixes existed. Patch planning should start from that record, because the vendor's no-exploitation note covers only the present.
  • decision A single firmware upgrade on either supported train closes all four bugs. That leaves operators no triage between them, only the choice of how soon internet-facing gateways get it.

Of the four, CVE-2026-102255 is the only one an attacker can use with nothing more than network access to the portal [5]. The other three need a login, and two of them need an administrator's [7][8]. Help Net Security puts the root cause down to an unintended alternate access path in the Work Place interface [4].

The SSRF's reach could change that ordering. According to Help Net Security, it lets an unauthenticated attacker perform actions normally reserved for logged-in users or admins [5]. The report does not say whether those actions reach the code behind CVE-2026-102256, the command injection fixed in the same release [7]. If they do, the two bugs together would give an attacker with no credentials operating system commands on the gateway [13].

"There is currently no evidence any of the vulnerabilities addressed in this release are being exploited in the wild," SonicWall said [2]. This year's record for this bug class points the other way. Attackers exploited two earlier pre-authentication SSRF flaws in SMA 1000, CVE-2026-15409 and CVE-2026-83548, as zero-days in 2026 [3]. Counting this release, at least three pre-auth SSRFs in the product line have gone public this year, and two of them were exploited before a fix existed [12]. Help Net Security also notes that past reports show both SMA 1000 and SMA 100 appliances are regularly targeted [10].

That makes this a pattern of repeated attacks on one product line. One exploit would have been a one-off. The two earlier zero-days are public record. Whether anyone is already working on CVE-2026-102255 is not known, and SonicWall's statement covers only what the company has seen so far [2].

SMA 1000 boxes are SSL VPN gateways used by medium and large enterprises, managed security service providers and government agencies [11]. They sit at the network edge by design, and the vulnerable Work Place portal is the internet-facing one [5].

What to watch

  • Publication of a proof-of-concept or technical write-up for CVE-2026-102255.
  • SonicWall revising its advisory to report in-the-wild exploitation of any of the four flaws.
  • Any statement from SonicWall or Benoît Sevens on whether the SSRF reaches CVE-2026-102256 without credentials.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence72
Adoption30
Hype gap+8
Incentives
Insufficient
Confidence70

Perspective Coverage

4 publishers
Builder
Builder 23%
Operator
Operator 67%
Investor
Investor 10%
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    SonicWall patched four vulnerabilities in its Secure Mobile Access (SMA) 1000 series, including CVE-2026-102255, which could allow remote unauthenticated attackers "to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations."

    ReportedSupportedSource: Help Net Security, quoting SonicWall4 sources— create a free account to open themView cited source
  2. [2]

    "There is currently no evidence any of the vulnerabilities addressed in this release are being exploited in the wild,"

    ReportedSupportedSource: SonicWall, as quoted by Help Net Security4 sources— create a free account to open themView cited source
  3. [3]

    In 2026, two pre-authentication server-side request forgery flaws (CVE-2026-15409, CVE-2026-83548) in SonicWall's SMA 1000 appliances have been leveraged as zero-days.

    ReportedSupportedSource: Help Net Security4 sources— create a free account to open themView cited source

Sources

4 independent publishers whose own reporting we read for this story.

  1. bleepingcomputer.com

    1 article · October 7, 2026

    SonicWall warns of max severity SSRF flaw in SMA1000 gateways
  2. helpnetsecurity.com

    1 article · October 7, 2026

    SonicWall fixes pre-auth SSRF flaw in SMA 1000 appliances (CVE-2026-102255)
  3. securityaffairs.com

    1 article · October 7, 2026

    SonicWall Fixes Max Severity Pre-Auth Flaw in SMA1000 Appliances
  4. thehackernews.com

    2 articles · October 8, 2026

    SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Entities

Loading related stories