SonicWall Patches CVSS 10 Pre-Auth SSRF in SMA1000

SonicWall patched four SMA1000 flaws, including a maximum-severity pre-auth SSRF in WorkPlace, urging users on older builds to apply hotfixes.

Read as article

SonicWall Patches CVSS 10 Pre-Auth SSRF in SMA1000

By @sharedot · · 7 pages

  • Cybersecurity
  • Sonicwall
  • Sma1000
  • Vulnerability
  • Ssrf

SonicWall patched four SMA1000 flaws, including a maximum-severity pre-auth SSRF in WorkPlace, urging users on older builds to apply hotfixes.

What happened: a CVSS 10 flaw anyone could reach

SonicWall released hotfixes on October 6, 2026 (advisory SNWLID-2026-0017) for four vulnerabilities in its SMA1000 remote access appliances. The worst, CVE-2026-102255, is a server-side request forgery in the WorkPlace portal rated 10.0 on the CVSS scale. It stems from an unintended alternate access path that lets the appliance act as a forward proxy, so a remote attacker with no valid credentials can make the device issue requests on their behalf, reach internal functions and perform unauthorized operations. The attack is network-accessible, low complexity, and requires no user interaction, making it the standout of the four fixes.

Why it is surprising: third max-severity SSRF this year

According to The Hacker News, this is the third time in 2026 that SonicWall has fixed a 10.0-rated, no-login SSRF flaw in WorkPlace, after CVE-2026-15409 and CVE-2026-15410 in July and CVE-2026-83548 and CVE-2026-83549 in September. Both earlier pairs were confirmed exploited in the wild, with the July chain letting attackers gain root access. Compounding the risk, the September fix versions — 12.4.3-03526 and 12.5.0-02952 — are themselves listed as affected by the new advisory, so September patching offers no protection here.

The evidence: four flaws, outside researchers credited

All four bugs affect SMA1000 models 6210, 7210 and 8200v. The others require authentication: CVE-2026-102256 (CVSS 7.8) is an OS command injection that could yield remote code execution under specific conditions; CVE-2026-102257 (CVSS 7.2) is a Zip Slip path-traversal flaw in the Appliance Management Console that can also lead to RCE; and CVE-2026-102258 (CVSS 5.5) is stored XSS in AMC. Benoît Sevens of Anthropic reported the SSRF and command-injection flaws, while Brian Mariani reported the Zip Slip issue through Trend Micro's Zero Day Initiative as ZDI-CAN-28924. SonicWall says it has no evidence of exploitation of these four, and the advisory does not establish that the SSRF can be chained with the others.

The stakes: edge VPN appliances as prime targets

SMA1000 appliances are the gateways remote workers rely on to reach corporate networks, and attackers have repeatedly targeted edge VPN products this year. Ransomware gangs have hit Palo Alto, Fortinet, Citrix and Check Point VPNs, and SonicWall's own July and September WorkPlace flaws saw real-world exploitation. The distinction matters for scoping: SSL-VPN on SonicWall firewalls and the SMA 100 Series are not affected, so administrators should verify exactly which devices run SMA1000 firmware before triaging.

What comes next: hotfix now, no workaround exists

Fixed builds are 12.4.3-03670 or later and 12.5.0-03082 or later, available through the MySonicWall portal; the appliance restarts when installation completes, and SonicWall lists no workaround. Unlike the July and September advisories, which directed customers to hunt for indicators of compromise, re-image or redeploy appliances, rotate passwords and reset TOTP tokens, SonicWall has given no such instructions for these four flaws. Teams still on 12.4.3-03526 or 12.5.0-02952 should not treat September's update as proof of protection.

Sources

  1. cybersecuritynews.com › SonicWall Patches 4 SMA1000 Flaws, Including Critical Pre-Auth SSRF Rated CVSS 10
  2. thehackernews.com › SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances
  3. securityaffairs.com › SonicWall Fixes Max Severity Pre-Auth Flaw in SMA1000 Appliances

More on Cybersecurity