Protect.Computer
NEWS

SonicWall Patches Max-Severity SMA1000 Flaw CVE-2026-102255

· 1 min read · Network safety
SonicWall Patches Max-Severity SMA1000 Flaw CVE-2026-102255

SonicWall has released hotfixes for CVE-2026-102255, a maximum-severity server-side request forgery (SSRF) flaw in SMA1000 series secure remote access appliances. BleepingComputer reports the bug sits in the Appliance WorkPlace interface and comes from an unintended alternate access path. A remote attacker with no privileges could exploit it in a low-complexity attack to make the appliance send requests on their behalf, reach internal functionality and perform unauthorized operations.

SonicWall says there is currently no evidence of exploitation in the wild, but urged customers to deploy the hotfixes released Tuesday. SMA1000 gateways are a frequent target: BleepingComputer notes that two zero-days (CVE-2026-15409 and CVE-2026-15410) were exploited in July, and that attackers chained two more (CVE-2026-83548 and CVE-2026-83549) last month. Shadowserver tracks over 400 internet-exposed SMA1000 appliances, though some may already be patched.

How to check if you’re affected

Affected models are the SonicWall SMA1000 6210, 7210 and 8200v appliances. The SMA 100 Series and SSL-VPN on SonicWall firewalls are not affected. If you run one of these appliances, check the installed firmware version against the fixed release listed in SonicWall’s advisory SNWLID-2026-0017 and apply the hotfix.

Sources

Related reading