Back to Articles
critical CVE-2026-102255

CRITICAL: SonicWall Fixes Another CVSS 10.0 Pre-Auth SSRF in SMA1000

SonicWall has patched CVE-2026-102255, a CVSS 10.0 pre-authentication SSRF in the SMA1000 WorkPlace portal, along with three other flaws. It is the third maximum severity SSRF in the product since July, and the previous two were exploited before patches shipped.

By Danny Mercer, CISSP — Lead Security Analyst • Oct 8, 2026
Is your business exposed? Our McKinney-based security team can assess your risk for free.
Share:

If you run SonicWall Secure Mobile Access 1000 appliances, you may be feeling a little like the guy who keeps getting called back to the same house fire. For the third time since July, SonicWall has shipped a fix for a maximum severity, pre-authentication server-side request forgery bug in the SMA1000 WorkPlace portal. This one is tracked as CVE-2026-102255, it carries a perfect CVSS score of 10.0, and it lets an attacker who has never logged in convince the appliance to make requests on their behalf and reach functionality that was never supposed to be exposed to the internet.

SonicWall published advisory SNWLID-2026-0017 on October 6, 2026, covering four vulnerabilities in total. The company says it has no evidence that any of them are being exploited in the wild yet. That is good news, and you should enjoy it for about as long as it takes to schedule a maintenance window. The last two times SonicWall disclosed a 10.0 rated SSRF in this exact product line, attackers were already using it. There is no reason to assume the people who went after the July and September bugs have lost interest in the box.

What CVE-2026-102255 actually does

The SMA1000 is SonicWall's enterprise remote access platform, the bigger sibling of the SMA 100 series, and WorkPlace is the web portal users hit when they log in to reach internal applications. SonicWall describes CVE-2026-102255 as an unintended alternate access path that allows a remote, unauthenticated attacker to direct the appliance to issue requests and perform unauthorized operations. In plain English, the portal can be talked into acting as a proxy for someone on the outside, and because the appliance sits in a privileged spot between the internet and your internal network, the requests it makes carry a level of trust that an outside attacker would never get on their own.

SSRF bugs tend to get undersold because the initial primitive sounds boring. The appliance makes a web request. So what? The answer is that those requests can reach internal management interfaces, localhost services on the appliance itself, cloud metadata endpoints on the virtual models, and backend systems that assume anything coming from the VPN concentrator is friendly. A 10.0 score means SonicWall's own assessment puts this at network reachable, low complexity, no privileges, no user interaction, and with impact that crosses a security boundary. That is the vendor telling you, in the most polite language a PSIRT team can manage, that this is very bad.

The other three bugs in the advisory are less dramatic on their own but worth understanding because they chain nicely. CVE-2026-102256 is an OS command injection flaw rated 7.8 that requires administrator privileges and allows arbitrary command execution on the appliance. CVE-2026-102257 is a Zip Slip issue rated 7.2 in the Appliance Management Console, where a specially crafted archive can write files outside the intended directory and lead to remote code execution for an authenticated user. CVE-2026-102258 rounds things out as a stored cross-site scripting bug rated 5.5, also in the management console and also requiring admin access. Any attacker who has spent time on SMA1000 exploitation this year will look at a pre-auth SSRF sitting next to a post-auth command injection and see an obvious path from internet to root. SonicWall has not said these can be chained, and I am not claiming a working chain exists. I am saying that is exactly the math the people who exploited the last two rounds will be doing this week.

Researcher Benoît Sevens is credited with finding both CVE-2026-102255 and CVE-2026-102256, while Brian Mariani of DigitalCanion SA reported the two management console bugs.

Affected versions and fixes

The vulnerable hardware and virtual appliances are the SMA1000 models 6210, 7210, and 8200v. On the 12.4.3 branch, platform hotfix 12.4.3-03526 and every earlier build are affected, and the fix is 12.4.3-03670 or later. On the 12.5.0 branch, platform hotfix 12.5.0-02952 and earlier builds are affected, and the fix is 12.5.0-03082 or later. Updates are available through mysonicwall.com.

SonicWall is clear that SSL-VPN on its firewalls and the SMA 100 series are not affected by any of these four flaws, so if your remote access runs through a TZ or NSa firewall you can take a breath. SonicWall also lists no workaround. There is no configuration toggle that closes this hole, so the patch is the mitigation.

Why the history matters here

It would be easy to read "no known exploitation" and drop this into next month's patch cycle. Please do not. The SMA1000 has been a favorite target all year, and the pattern is hard to ignore. On July 14, 2026, SonicWall disclosed CVE-2026-15409 and CVE-2026-15410, a pair of SMA1000 flaws that included a 10.0 rated pre-auth SSRF, and the company acknowledged they had been exploited in multiple cases. Seven weeks later, on September 1, it disclosed CVE-2026-83548 and CVE-2026-83549, another pair headlined by a 10.0 pre-auth SSRF in the same WorkPlace interface, and once again confirmed exploitation in at least one case before customers had a patch.

So this is now three maximum severity, unauthenticated SSRF bugs in the same portal in roughly twelve weeks. When a component produces that many findings in a row, it usually means researchers on both sides of the fence have figured out where the soft tissue is and are working through it methodically. Patch diffing a fresh SonicWall hotfix is a well rehearsed exercise for the crews that target edge devices, and the gap between "no evidence of exploitation" and "added to the CISA KEV catalog" for SMA1000 bugs this year has been short enough that nobody should be betting on a quiet month.

There is also a broader trend at play. Remote access appliances remain the single most reliable front door into enterprise networks because they have to be reachable from the internet, they hold credentials and session tokens, and they are often managed by a team that treats them as set and forget infrastructure. Ivanti, Fortinet, Citrix, Cisco, Palo Alto, and SonicWall have all had their turn in this barrel. The FBI warning this week that the FortiBleed campaign has harvested more than 86,000 Fortinet device credentials is a useful reminder of what happens when edge devices stay unpatched while attackers industrialize the exploitation.

What to do right now

Start with inventory. Find every SMA1000 6210, 7210, and 8200v in your environment or your clients' environments, including the virtual appliances someone spun up in a cloud tenant for a project two years ago and forgot about. Check the running platform hotfix version against the fixed builds above, and if you are on 12.4.3-03526 or 12.5.0-02952 or anything older, upgrade to 12.4.3-03670 or 12.5.0-03082 as soon as you can get a window. For most organizations that window should be this week, not next month.

If you were affected by the July or September issues, treat this update as a good moment to revisit whether those incidents were fully closed out. Appliances that were compromised earlier in the year and only patched, rather than rebuilt and rotated, may still be carrying persistence that a new firmware build will not remove. Rotating credentials stored on or passed through the appliance, including any service accounts it uses for LDAP or Active Directory lookups, is cheap insurance.

While you wait for the maintenance window, reduce the attack surface. Restrict access to the Appliance Management Console so it is reachable only from a dedicated management network and never from the internet. If your business can tolerate it, put the WorkPlace portal behind an additional layer such as geo-restrictions or an upstream web application firewall rule set, keeping in mind that none of this replaces the patch.

For detection, focus on the appliance acting strangely rather than on a specific signature, because no public proof of concept has surfaced yet. Look at WorkPlace access logs for unauthenticated requests carrying unusual URL parameters, encoded hostnames, internal IP addresses, or references to localhost and loopback addresses. Watch for outbound connections from the SMA1000 to destinations it has no business talking to, including internal management ports and cloud metadata addresses on virtual deployments. New administrator accounts, unexpected configuration exports, archive uploads to the management console, and child processes spawned from the web service are all worth an immediate investigation. If you feed appliance logs into a SIEM, build a baseline of normal WorkPlace traffic now so the oddities stand out when exploitation attempts start.

Finally, keep an eye on CISA's Known Exploited Vulnerabilities catalog and SonicWall's PSIRT page over the coming days. If CVE-2026-102255 shows up in KEV, any appliance still unpatched should be assumed hostile until proven otherwise.

The bottom line

SonicWall deserves some credit for finding and fixing this one before attackers did, which is a better outcome than the last two rounds. But a 10.0 pre-auth SSRF in a product that has been actively exploited twice in three months is about as close to a guaranteed future incident as this industry offers. Patch the SMA1000 fleet now, lock down the management console, and go hunting through your logs while you are at it.

The MSP angle

Three critical SMA1000 advisories in one quarter make an easy and honest case for managed edge device patching with a guaranteed turnaround, and clients who get a call from you about this before they read about it elsewhere tend to remember it at renewal time. It is also a natural opening to pitch an external attack surface assessment and a conversation about moving off aging VPN appliances toward a zero trust access model.

References

Concerned about this threat?

Our security team can assess your exposure and recommend immediate actions.

Get a Free Assessment →