SonicWall SMA1000 CVE-2026-102255 is CVSS 10
Pre-auth SSRF on SMA 1000 Work Place, hotfix required

SonicWall SMA1000 CVE-2026-102255 is CVSS 10

SonicWall patched four flaws in SMA 1000 remote-access appliances on 6 October 2026. The worst is CVE-2026-102255, a pre-authentication server-side request forgery scored 10.0. An outsider can send a crafted request to the internet-facing Work Place portal and make the appliance call internal functions that trust it.

What happened

The bug is an unintended alternate access path in Work Place. SonicWall says it has no evidence that any of the four flaws in this release is being exploited. Two earlier SMA 1000 pre-auth SSRF bugs, CVE-2026-15409 and CVE-2026-83548, were used as zero-days this year, so this one should not sit in a change window.

The same advisory also covers CVE-2026-102256, a post-auth OS command injection, plus admin-only path traversal and stored cross-site scripting in the Appliance Management Console.

Who is affected

  • Physical and virtual SMA 1000 models 6210, 7210, and 8200v.
  • 12.4.3 branch through 12.4.3-03526. Fixed in 12.4.3-03670 and later.
  • 12.5.0 branch through 12.5.0-02952. Fixed in 12.5.0-03082 and later.
  • SonicWall firewall SSL-VPN and the SMA 100 Series are not affected. Those September builds were the fix for the last exploited pair, so an appliance left on them is still exposed to this new bug.

What to do now

Install 12.4.3-03670 or 12.5.0-03082 from mysonicwall.com, then confirm Work Place is not reachable from the open internet unless a client actually needs it. Restrict management to a known admin network. If the appliance was internet-facing before the hotfix, review admin accounts and session logs for unexpected access.

Source: Help Net Security, 7 October 2026. SonicWall fixes pre-auth SSRF flaw in SMA 1000 appliances. Vendor notice: SNWLID-2026-0017.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

ASOS confirms breach after app alert claimed Snowflake access
Retailer says names and contact details may be exposed, not card data