SonicWall Patches Maximum-Severity SMA1000 Flaw
SonicWall released hotfixes for CVE-2026-102255, a maximum-severity SSRF flaw in SMA1000 appliances, and urged customers to apply them.
SonicWall has released hotfixes for a maximum-severity server-side request forgery (SSRF) vulnerability affecting its SMA1000 series appliances, according to BleepingComputer. The flaw is tracked as CVE-2026-102255.
The vulnerability was found in the Appliance WorkPlace interface of the SMA1000 6210, 7210, and 8200v models. It stems from an unintended alternate access-path weakness that remote, unprivileged attackers can exploit in low-complexity attacks.
SonicWall said the flaw does not affect the SMA 100 Series product line or SSL-VPN running on SonicWall firewalls. The company has not flagged the vulnerability as actively exploited in the wild, and urged customers to deploy the hotfixes released on Tuesday.
Shadowserver currently tracks more than 400 internet-exposed SMA1000 appliances, leaving a potentially broad pool of devices in scope for patching.
Recent SMA1000 Attacks
In July, two SMA1000 zero-days, CVE-2026-15409 and CVE-2026-15410, were exploited for weeks to install custom Sou5, OrangeTail, and RootRun malware on vulnerable VPN appliances, in attacks CISA linked to ransomware gangs. Last month, SonicWall warned that attackers were chaining two new zero-days, CVE-2026-83548 and CVE-2026-83549, to execute remote code on vulnerable SMA1000 gateways.
CISA has added 19 SonicWall vulnerabilities to its list of actively exploited flaws over the last four years, 13 of which have also been abused in ransomware attacks.
Quick answers
Which SonicWall products are affected by CVE-2026-102255?
The SSRF flaw affects the SMA1000 6210, 7210, and 8200v models through the Appliance WorkPlace interface. SonicWall said the SMA 100 Series and SSL-VPN on SonicWall firewalls are not affected.
Is CVE-2026-102255 being exploited in the wild?
SonicWall has not flagged the flaw as actively exploited in the wild, but it urged customers to deploy the hotfixes released on Tuesday.
How many SMA1000 appliances are exposed online?
Shadowserver currently tracks over 400 internet-exposed SMA1000 appliances.