Read as article
SonicWall Patches CVSS 10 Pre-Auth SSRF in SMA1000
By @sharedot · · 7 pages
- Cybersecurity
- Sonicwall
- Sma1000
- Vulnerability
- Ssrf
SonicWall patched four SMA1000 flaws, including a maximum-severity pre-auth SSRF in WorkPlace, urging users on older builds to apply hotfixes.
What happened: a CVSS 10 flaw anyone could reach
SonicWall released hotfixes on October 6, 2026 (advisory SNWLID-2026-0017) for four vulnerabilities in its SMA1000 remote access appliances. The worst, CVE-2026-102255, is a server-side request forgery in the WorkPlace portal rated 10.0 on the CVSS scale. It stems from an unintended alternate access path that lets the appliance act as a forward proxy, so a remote attacker with no valid credentials can make the device issue requests on their behalf, reach internal functions and perform unauthorized operations. The attack is network-accessible, low complexity, and requires no user interaction, making it the standout of the four fixes.
Why it is surprising: third max-severity SSRF this year
According to The Hacker News, this is the third time in 2026 that SonicWall has fixed a 10.0-rated, no-login SSRF flaw in WorkPlace, after CVE-2026-15409 and CVE-2026-15410 in July and CVE-2026-83548 and CVE-2026-83549 in September. Both earlier pairs were confirmed exploited in the wild, with the July chain letting attackers gain root access. Compounding the risk, the September fix versions — 12.4.3-03526 and 12.5.0-02952 — are themselves listed as affected by the new advisory, so September patching offers no protection here.
The evidence: four flaws, outside researchers credited
All four bugs affect SMA1000 models 6210, 7210 and 8200v. The others require authentication: CVE-2026-102256 (CVSS 7.8) is an OS command injection that could yield remote code execution under specific conditions; CVE-2026-102257 (CVSS 7.2) is a Zip Slip path-traversal flaw in the Appliance Management Console that can also lead to RCE; and CVE-2026-102258 (CVSS 5.5) is stored XSS in AMC. Benoît Sevens of Anthropic reported the SSRF and command-injection flaws, while Brian Mariani reported the Zip Slip issue through Trend Micro's Zero Day Initiative as ZDI-CAN-28924. SonicWall says it has no evidence of exploitation of these four, and the advisory does not establish that the SSRF can be chained with the others.
The stakes: edge VPN appliances as prime targets
SMA1000 appliances are the gateways remote workers rely on to reach corporate networks, and attackers have repeatedly targeted edge VPN products this year. Ransomware gangs have hit Palo Alto, Fortinet, Citrix and Check Point VPNs, and SonicWall's own July and September WorkPlace flaws saw real-world exploitation. The distinction matters for scoping: SSL-VPN on SonicWall firewalls and the SMA 100 Series are not affected, so administrators should verify exactly which devices run SMA1000 firmware before triaging.
What comes next: hotfix now, no workaround exists
Fixed builds are 12.4.3-03670 or later and 12.5.0-03082 or later, available through the MySonicWall portal; the appliance restarts when installation completes, and SonicWall lists no workaround. Unlike the July and September advisories, which directed customers to hunt for indicators of compromise, re-image or redeploy appliances, rotate passwords and reset TOTP tokens, SonicWall has given no such instructions for these four flaws. Teams still on 12.4.3-03526 or 12.5.0-02952 should not treat September's update as proof of protection.