SonicWall patches critical SSRF bug in SMA1000 remote-access gateways
SonicWall issued hotfixes for CVE-2026-102255, a maximum-severity server-side request forgery flaw in the Appliance WorkPlace interface of its SMA1000 6210, 7210, and 8200v gateways. The company says an unauthenticated attacker could exploit the flaw via an unintended access path to make the appliance issue requests on their behalf and reach internal functionality, though it has found no evidence of active exploitation.
GoKawiil's interpretation of the reporting above, not reported fact.
SMA1000 devices provide VPN access to internal networks for governments, MSSPs, and large enterprises, making them attractive targets even without confirmed exploitation. Shadowserver counts over 400 internet-exposed SMA1000 appliances, and SonicWall's product line has suffered zero-day attacks earlier this year, which suggests organizations should patch promptly rather than wait for proof of in-the-wild abuse.
- CVE-2026-102255 is a maximum-severity SSRF flaw in SMA1000 6210, 7210, and 8200v appliances.
- SonicWall released hotfixes and urges immediate upgrades; no active exploitation confirmed yet.
- Over 400 SMA1000 appliances remain internet-exposed, and the product line has seen zero-day attacks in 2026.
Source: bleepingcomputer.com, 2026-10-07
Published there as: “SonicWall warns of max severity SSRF flaw in SMA1000 gateways”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.