SonicWall patches maximum-severity pre-auth SSRF flaw in SMA 1000 gateways
SonicWall has released hotfixes for CVE-2026-102255, an unauthenticated server-side request forgery flaw in SMA 1000 appliances that could let attackers reach internal functions.
At a glance
- CVE-2026-102255 is a pre-authentication SSRF in the SMA 1000 Workplace interface, rated maximum severity.
- Affected models are the SMA 6210, 7210 and 8200v; SMA 100 and firewall SSL-VPN are not affected.
- Fixed in firmware 12.4.3-03670 and 12.5.0-03082 or later; no exploitation reported yet.
- Shadowserver tracks more than 400 internet-exposed SMA 1000 appliances.
SonicWall has warned customers to patch a maximum-severity vulnerability in its Secure Mobile Access (SMA) 1000 series remote access gateways. The flaw, tracked as CVE-2026-102255, is a server-side request forgery (SSRF) issue that can be exploited remotely without authentication, according to BleepingComputer. The company released hotfixes on October 7, 2026. Although there are no reports of attacks yet, SMA appliances have been a recurring target for attackers this year, which makes rapid patching important.
What happened
SonicWall said the bug stems from an unintended alternate access path in the appliance's Workplace interface. In the company's words, "a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations." BleepingComputer described the attack as low in complexity.
Help Net Security reported that the issue was found by researcher Benoît Sevens. SonicWall stated that there is currently no evidence that any of the vulnerabilities addressed in the release are being exploited in the wild.
Who is affected
The vulnerability affects SMA 1000 models 6210, 7210 and 8200v, including physical and virtual appliances. SonicWall said the SMA 100 series and the SSL-VPN feature on SonicWall firewalls are not affected. According to BleepingComputer, the Shadowserver Foundation tracks more than 400 SMA 1000 appliances exposed to the internet.
These gateways are used by government agencies and large enterprises to provide remote access to internal networks. BleepingComputer noted that SMA 1000 flaws have been repeatedly targeted since January 2026, and Help Net Security said two other pre-authentication SSRF vulnerabilities in SonicWall's SMA products were exploited as zero-days this year. CISA has added 19 SonicWall vulnerabilities to its Known Exploited Vulnerabilities catalog over the past four years, BleepingComputer said.
What to do
Administrators should upgrade SMA 1000 appliances to firmware 12.4.3-03670 or 12.5.0-03082 or later. No workaround has been published, so patching is the only listed fix. Given the history of attacks on these devices, organizations should also limit access to the management and Workplace interfaces where possible, review appliance logs for unusual outbound requests from the gateway, and monitor for unexpected configuration changes after updating.
Related CVEs
Sources
- SonicWall warns of max severity SSRF flaw in SMA1000 gateways — BleepingComputer
- SonicWall fixes pre-auth SSRF flaw in SMA 1000 appliances (CVE-2026-102255) — Help Net Security
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



