SonicWall Releases Hotfix for Critical CVE-2026-102255 SSRF Flaw in SMA1000 Appliances
SonicWall has released a hotfix for CVE-2026-102255, a maximum-severity Server-Side Request Forgery (SSRF) vulnerability affecting SMA1000 series appliances.
CVE-2026-102255 affects the SMA1000 Appliance WorkPlace interface
Tracked as CVE-2026-102255, the vulnerability was found in the Appliance WorkPlace interface.
The flaw affects the SMA1000 6210, 7210, and 8200v models. It does not affect SSL-VPN running on the SMA100 series product line or SonicWall firewalls.
SonicWall says the vulnerability is caused by an unintended alternate access path weakness. An unprivileged remote attacker could exploit the flaw through a low-complexity attack.
“By exploiting this path, a remote, unauthenticated attacker could exploit this vulnerability to instruct the appliance to issue requests on its behalf, reach internal functionality, and perform unauthorized operations,” SonicWall said.
SonicWall urges customers to install the SMA1000 hotfix
The company has not flagged CVE-2026-102255 as actively exploited. However, SonicWall urged customers to deploy the hotfix released Tuesday to protect virtual and physical appliances from potential attacks.
“SonicWall strongly recommends that users of SMA1000 series appliances upgrade to the fixed release versions listed above to address these vulnerabilities,” the company said. “At this time, there is no evidence that the vulnerabilities addressed in this release are being exploited in the wild.”
More than 400 SMA1000 appliances exposed online
Internet security threat watchdog Shadowserver is currently tracking more than 400 Internet-exposed SMA1000 appliances. Some of these devices have already been patched.

SMA1000 appliances have been repeatedly targeted
Although CVE-2026-102255 has not been exploited in the wild, attackers frequently target SMA1000 vulnerabilities because the appliances provide secure remote access to internal applications and corporate networks.
The enterprise-grade gateways are used by government agencies, managed service providers (MSSPs), and large organizations to provide VPN access.
Attackers have exploited several SMA1000 security vulnerabilities in zero-day attacks since the beginning of this year.
In July, two SMA1000 zero-days, CVE-2026-15409 and CVE-2026-15410, were exploited over several weeks in an attack that the U.S. Cybersecurity and Infrastructure Security Agency (CISA) linked to ransomware gangs. The attackers used the vulnerabilities to install custom Sou5, OrangeTail, and RootRun malware on vulnerable VPN appliances.
Last month, SonicWall warned customers that attackers had chained two new zero-days, CVE-2026-83548 and CVE-2026-83549, to execute remote code on vulnerable SMA1000 gateways.
CISA has added 19 SonicWall vulnerabilities to its Known Exploited Vulnerabilities catalog. During the past four years, 13 of those vulnerabilities were also used in ransomware attacks.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



