SonicWall has released hotfixes to address a maximum-severity server-side request forgery (SSRF) flaw in SMA1000 series appliances.
Tracked as CVE-2026-102255, the vulnerability was found in the Appliance WorkPlace interface of SMA1000 6210, 7210, and 8200v models, but it does not affect the SMA 100 Series product line or SSL-VPN running on SonicWall firewalls.
The flaw stems from an unintended alternate access-path weakness that remote attackers without privileges can exploit in low-complexity attacks.
“By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations,” SonicWall explained.
While it has not yet flagged these flaws as actively exploited, the company urged customers to deploy hotfixes released on Tuesday to block potential attacks targeting their virtual or physical appliances.
“SonicWall strongly advises users of the SMA1000 series appliances to upgrade to the mentioned fixed release version to address these vulnerabilities,” the company added. “There is currently no evidence any of the vulnerabilities addressed in this release are being exploited in the wild.”
Internet security threat watchdog Shadowserver currently tracks over 400 Internet-exposed SMA1000 appliances, although some may have already been patched.
Although CVE-2026-102255 is not exploited in the wild, attackers often target SMA1000 flaws because they affect enterprise-grade secure remote access gateways used by government agencies, Managed Service Providers (MSSPs), and many large corporations to provide VPN access to internal apps and corporate networks.
Since the start of the year, threat actors have exploited several SMA1000 security vulnerabilities in zero-day attacks.
In July, two SMA1000 zero-days (CVE-2026-15409 and CVE-2026-15410) were exploited for weeks to install custom Sou5, OrangeTail, and RootRun malware on vulnerable VPN appliances in attacks that the U.S. Cybersecurity and Infrastructure Security Agency (CISA) linked to ransomware gangs.
Last month, SonicWall also warned customers that attackers were chaining two new zero-days (CVE-2026-83548 and CVE-2026-83549) to execute remote code on vulnerable SMA1000 gateways.
CISA has added 19 SonicWall vulnerabilities to its list of actively exploited flaws over the last four years, 13 of which have also been abused in ransomware attacks.
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
SonicWall warns of actively exploited SMA1000 zero-day flaws
SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now
Sonicwall warns of new SMA1000 zero-day exploited in attacks
CISA warns of hackers exploiting critical MLflow vulnerability
Anthropic asks Claude users to share voice data for AI model training
Citrix patches NetScaler SAML zero-day exploited in attacks
New Dell System Update flaw lets hackers gain root privileges
Free Identity Governance for up to 150 Users: Try Our Community Edition
73% of orgs feel prepared for attacks. 82% had a browser incident last year anyway.
Your access review passed cleanly, but it never saw the agents swimming under the surface. See how Token Security fishes out every one of them.
Overdue a password health-check? Audit your Active Directory for free
Learn how to evaluate RMM security with eight practical tests. Find gaps before scaling endpoint management across customer environments.
Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure
Read our posting guidelinese to learn what content is prohibited.



