SonicWall patches pre-auth SSRF flaw in SMA 1000 VPNs
SonicWall has released hotfixes for four vulnerabilities in its Secure Mobile Access (SMA) 1000 series appliances. The most serious, CVE-2026-102255, can be exploited by remote attackers who have not logged in.
According to the vendor, the flaw could let an unauthenticated attacker "to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations."
SonicWall says it has seen no sign that any of the four bugs is being exploited. That may not last. SMA appliances, both the 1000 and the older 100 series, have been frequent targets for attackers, and similar bugs in the same product line have already been used in real attacks.
A familiar class of bug
The SMA 1000 line consists of SSL VPN gateways. Medium and large enterprises, managed security service providers (MSPs) and government agencies use them to give remote users access to internal resources. Because these gateways sit at the edge of the network and face the internet, they are attractive targets.
CVE-2026-102255 is a server-side request forgery (SSRF) vulnerability that can be triggered before authentication. In an SSRF attack, the attacker tricks a server into sending requests on their behalf. This one sits in the appliance's Work Place interface, the portal users reach from the internet. SonicWall attributes it to "an unintended alternate access path."
In practice, an attacker can send a crafted request to the portal. The appliance then makes requests to internal endpoints that trust it. This allows the attacker to carry out actions that should only be available to logged-in users or administrators.
This year, two other pre-authentication SSRF flaws in SMA 1000 appliances, CVE-2026-15409 and CVE-2026-83548, were exploited as zero-days, meaning attackers used them before patches were available. The new bug belongs to the same class and affects the same product line, so the vendor's warning about likely exploitation is easy to understand.
The other three flaws
The remaining vulnerabilities are harder to abuse, because each one requires the attacker to be logged in first.
CVE-2026-102256 is an OS command injection flaw that can be exploited after authentication. Benoît Sevens reported it, along with CVE-2026-102255.
Researcher Brian Mariani reported the other two, both found in the Appliance Management Console:
- CVE-2026-102257, a path traversal flaw
- CVE-2026-102258, a cross-site scripting (XSS) flaw
Both can only be exploited by an attacker who is authenticated as an administrator.
Affected models and fixes
The bugs affect the physical and virtual SMA 1000 models 6210, 7210 and 8200v. SonicWall has fixed all four and advises customers to move to one of these hotfix firmware versions:
- 12.4.3-03670 or higher
- 12.5.0-03082 or higher
SonicWall firewalls are not affected. The SMA 100 series is also not affected, but it has been discontinued and is no longer supported.
Why It Matters
For organisations running SMA 1000 gateways, the priority is clear: install the hotfix soon, even though no attacks have been reported yet. A pre-authentication flaw on an internet-facing VPN portal needs no stolen credentials and no user interaction. That is exactly the kind of entry point attackers look for first.
The track record is the main concern. Two earlier pre-auth SSRF bugs in this product line were exploited as zero-days this year, which suggests that attackers already know the SMA 1000 attack surface well. A patch also makes a new bug easier to find, because researchers and criminals can compare the fixed and unfixed code. It is worth watching whether exploitation attempts against CVE-2026-102255 appear in the coming weeks.
The case also fits a wider pattern. Network edge devices from several vendors have been under steady pressure, as recent incidents such as the Citrix NetScaler SAML zero-day and the exploited Cisco SD-WAN Manager flaw show. VPN gateways and similar appliances often hold privileged positions inside networks and are harder to monitor than ordinary endpoints. For defenders, this means regular patching may not be enough on its own. It also helps to limit who can reach management interfaces, review appliance logs for unusual internal requests, and keep an up-to-date inventory of every device exposed to the internet.
Organisations still using the discontinued SMA 100 series face a different problem. Those devices are not affected by these specific bugs, but they no longer receive support. That leaves owners exposed if future flaws are found.
