Skip to content

Security1 publisherNot yet confirmed elsewhere2 min readPublished

SonicWall patches a CVSS 10 pre-login SSRF flaw in its SMA1000 appliances

SonicWall patched four SMA1000 flaws, led by CVE-2026-102255, a CVSS 10 request-forgery bug that an attacker can use without logging in. The company says none of the four is being exploited, so owners who update now are ahead of any known attack.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying SonicWall patches a CVSS 10 pre-login SSRF flaw in its SMA1000 appliances
Generated illustration

What happened

  • SonicWall traces CVE-2026-102255 to an unintended alternate access path in the appliance.
  • The other three fixes cover two high-severity flaws and one medium-severity flaw that can be exploited for remote code execution and cross-site scripting.
  • SonicWall is urging SMA1000 users to update to version 12.5.0-03082 or 12.4.3-03670 as soon as possible.
  • Splunk shipped fixes the same Wednesday, including three critical Splunk Enterprise bugs allowing command execution, unauthorized access and code injection.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure The bug is reached before the login step, so passwords and MFA do not protect an unpatched SMA1000 from anyone who can send it traffic.
  • decision Teams that run SSL-VPN only on SonicWall firewalls can keep this release off their emergency change list, since SonicWall says that product is not affected.
  • cost Fixed builds ship on both the 12.5 and 12.4 lines, so owners on 12.4 can patch without first moving to a new release line.

Server-side request forgery lets the attacker use the appliance's own position on the network. The SMA1000 sends the requests itself, so an outsider can reach functions meant only for internal callers [5]. "By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations," SonicWall said [5].

In that description, the SSRF stops at "unauthorized operations" [5]. Code execution sits in the other three fixes [6]. An SMA1000 on an older build has both problems at once: a request path that works before login, and at least one flaw that can be exploited for remote code execution [12]. The SecurityWeek report does not say whether those other flaws need a login, and it ties no threat actor or earlier campaign to SMA1000 appliances [6].

So this is a vendor patch, and no incident has been reported against it [7]. The no-exploitation status comes from SonicWall alone and describes the day of release, Wednesday [1][7]. I'd rank the bug on reach. Anyone who can send traffic to the appliance can attempt it [3].

Splunk patched a related kind of bug the same day [1]. Its MCP Server had a medium-severity defect that let an authenticated user change API settings so the product sent requests to an attacker-controlled URL [11]. Both bugs make a product send requests to a destination the attacker picks. Splunk's needs a logged-in user. SonicWall's needs none [3][11].

What to watch

  • SonicWall publishing whether the two high-severity code-execution flaws require authentication, or whether the CVE-2026-102255 request path can reach them.
  • Any revision to SonicWall's no-exploitation statement, or a public proof-of-concept for CVE-2026-102255.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence58
Adoption
Insufficient
Hype gap+5
Incentives
Insufficient
Confidence62
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Splunk and SonicWall on Wednesday announced patches for multiple critical- and high-severity vulnerabilities in their products.

    ReportedSupportedSource: SecurityWeekView cited source
  2. [2]

    SonicWall rolled out fixes for four vulnerabilities in its SMA1000 appliances, urging users to update to versions 12.5.0-03082 and 12.4.3-03670 as soon as possible.

    ReportedSupportedSource: SecurityWeekView cited source
  3. [3]

    The most severe of the SMA1000 issues, CVE-2026-102255, has a CVSS score of 10 and is a pre-authenticated server-side request forgery (SSRF) bug.

    ReportedSupportedSource: SecurityWeekView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. securityweek.com

    1 article · October 8, 2026

    SonicWall and Splunk Patch Critical Vulnerabilities

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Entities

Loading related stories