CVE-2026-102255: CVSS 10 SSRF in SonicWall SMA1000
SMA1000 WorkPlace unauthenticated server-side request forgery

CVE-2026-102255: CVSS 10 SSRF in SonicWall SMA1000

SonicWall released hotfixes on 6 October 2026 for a maximum-severity flaw in SMA1000 remote-access gateways. CVE-2026-102255 is an unauthenticated server-side request forgery in the Appliance WorkPlace interface, scored CVSS 10.0. SonicWall says there is no evidence of exploitation yet. That is not a reason to wait.

What happened

The bug is an unintended alternate access path. A remote attacker with no account can make the appliance issue requests on their behalf, reach internal functionality, and perform unauthorised operations. The same notice also covers a high-severity remote code execution bug, CVE-2026-102256 (CVSS 7.8), a zip-slip path traversal, and a stored cross-site scripting issue.

SMA1000 flaws have a bad recent history. Earlier this year, zero-days on the same product line were used to install custom malware, and CISA later tied some of that activity to ransomware. Shadowserver was tracking more than 400 internet-exposed SMA1000 appliances when the hotfix landed.

Who is affected

SMA 1000 models 6210, 7210, and 8200v on firmware 12.4.3-03526 and older, or 12.5.0-02952 and older. The SMA 100 series and SSL-VPN on SonicWall firewalls are not affected by this notice.

  • Fixed builds: 12.4.3-03670 and higher, or 12.5.0-03082 and higher
  • WorkPlace interface is the vulnerable surface
  • Vendor advisory ID: SNWLID-2026-0017

What to do now

Apply 12.4.3-03670 or 12.5.0-03082 before the appliance stays on the internet over a weekend. If a client SMA1000 is exposed and you cannot patch today, restrict WorkPlace to known source addresses and confirm the box is not still on an older branch that missed the earlier zero-day fixes. After the hotfix, review admin sessions and outbound connections from the appliance.

Source: BleepingComputer, 7 October 2026, SonicWall warns of max severity SSRF flaw in SMA1000 gateways.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

FortiBleed: FBI says 86,644 Fortinet device credentials still in play
FortiGate SSL VPN credential harvesting and admin lockout