SonicWall has patched a maximum-severity security flaw in its SMA 1000 remote-access appliances that lets an attacker reach internal systems without a login. The vulnerability, tracked as CVE-2026-102255, carries a CVSS score of 10.0, the highest possible, and it is the third pre-authentication SSRF bug found in the same appliance interface this year. The two previous ones were both exploited in the wild within days.
The short answer: if your organization runs a SonicWall SMA 1000 appliance (models 6210, 7210, or 8200v) on version 12.4.3-03526 or older, or 12.5.0-02952 or older, you should install the hotfix from the MySonicWall portal immediately. Fixed versions are 12.4.3-03670 and 12.5.0-03082 or newer. SonicWall says it has no evidence of exploitation so far, but the pattern of the last two bugs argues against waiting.
What CVE-2026-102255 actually is
The flaw is a server-side request forgery (SSRF) in WorkPlace, the portal that SMA 1000 users log in through. SonicWall describes the root cause as an unintended alternate access path that lets the appliance act as a forward proxy before authentication happens. An unauthenticated attacker can push the appliance into issuing network requests on their behalf, reach internal functionality, and perform unauthorized operations.
SonicWall classifies the issue under CWE-918 (SSRF) and CWE-441 (unintended proxy, also known as a confused deputy). The CVSS 10.0 rating reflects a network-accessible attack path with low complexity and potential high impact across confidentiality, integrity, and availability. This is the kind of bug that sits directly on the network edge: the appliance itself is internet-facing by design, so the attacker never needs to compromise a user account first.
Which appliances and versions are affected
The advisory covers physical and virtual SMA 1000 series appliances, specifically the 6210, 7210, and 8200v models. The affected and fixed platform versions break down like this:
- Version 12.4.3: 12.4.3-03526 and older are affected; 12.4.3-03670 and newer are fixed.
- Version 12.5.0: 12.5.0-02952 and older are affected; 12.5.0-03082 and newer are fixed.
Notably, the affected versions include 12.4.3-03526 and 12.5.0-02952, which SonicWall named on September 1 as the fixes for two flaws it reported as exploited. So an appliance that is patched against the September bugs can still be vulnerable to this one. SonicWall confirms that SSL-VPN on its firewalls and the older SMA 100 series are not affected.
The three other flaws in the same advisory
Advisory SNWLID-2026-0017, published October 6, covers four flaws in total. The other three all sit in the Appliance Management Console (AMC), the interface administrators use to configure the box, and each requires valid administrator credentials before it can be exploited:
- CVE-2026-102256 – OS command injection, CVSS 7.8.
- CVE-2026-102257 – Zip Slip path traversal, CVSS 7.2.
- CVE-2026-102258 – Stored cross-site scripting, CVSS 5.5.
These are real bugs, but they matter far less than CVE-2026-102255 because an attacker must already hold AMC admin credentials to reach them. If someone has those credentials, the organization has a much bigger problem.
Why this one is being taken seriously
The uncomfortable part is the pattern. This is the third pre-authentication SSRF patched in the SMA 1000 Work Place interface in 2026. CVE-2026-15409 was patched in July and CVE-2026-83548 in September, and both were independently confirmed exploited in the wild shortly after disclosure, eventually landing in the CISA Known Exploited Vulnerabilities catalog. Attackers have repeatedly shown they can weaponize bugs in this exact component quickly.
SonicWall says it currently has no evidence of in-the-wild exploitation of CVE-2026-102255, and that may hold. But the same was true of the previous two at disclosure time, and internet scanning for exposed SMA appliances is routine. Internet-wide scans have found thousands of SonicWall SMA instances reachable online, which is why security teams treat a CVSS 10.0 pre-auth edge bug as a patch-now event rather than a patch-later one. This week alone has seen a cluster of edge-device emergencies, from the Citrix NetScaler SAML zero-day to the FortiMail zero-day that landed on the CISA KEV catalog.
What to do right now
If you manage an SMA 1000 appliance, the checklist is short:
- Check your firmware version. If you are on 12.4.3-03526 or older, or 12.5.0-02952 or older, you are affected.
- Apply the hotfix from the MySonicWall portal. SonicWall lists no workaround, so the upgrade is the only fix. The appliance restarts when installation finishes, so plan a short maintenance window.
- Verify the fix. After the restart, confirm you are on 12.4.3-03670 or 12.5.0-03082 or newer.
- Review exposure and logs. Because the two previous SSRF bugs in this interface were exploited, check for unexpected outbound requests or configuration changes in the window between September and patching.
The broader lesson, visible across recent enterprise advisories like the Atlassian file-access flaw disclosed this week, is that internet-facing management and access appliances need patching at emergency speed now. Attackers have proven they will move on pre-auth edge bugs within hours of disclosure.
Frequently asked questions
What is CVE-2026-102255?
It is a pre-authentication server-side request forgery (SSRF) vulnerability in the WorkPlace interface of SonicWall SMA 1000 appliances. Rated CVSS 10.0, it allows a remote unauthenticated attacker to make the appliance send requests on their behalf and reach internal functionality. SonicWall disclosed it in advisory SNWLID-2026-0017 on October 6, 2026.
Which SonicWall appliances are affected?
SMA 1000 series appliances, models 6210, 7210, and 8200v (physical and virtual), running platform version 12.4.3-03526 or older, or 12.5.0-02952 or older. SonicWall firewalls running SSL-VPN and the SMA 100 series are not affected.
Has CVE-2026-102255 been exploited in the wild?
SonicWall states it has no evidence of in-the-wild exploitation as of disclosure. However, the two previous pre-authentication SSRF bugs in the same interface (CVE-2026-15409 and CVE-2026-83548) were both exploited shortly after disclosure and added to the CISA KEV catalog, so affected systems should be patched without delay.
Is there a workaround for CVE-2026-102255?
No. SonicWall has not published any workaround or mitigation for this flaw. Installing the fixed hotfix (12.4.3-03670 or 12.5.0-03082 or newer) from the MySonicWall portal is the only remediation.
Does this affect me if I use a SonicWall firewall for SSL-VPN?
No. SonicWall confirms that SSL-VPN functionality on SonicWall firewalls and the discontinued SMA 100 series appliances are not affected by any of the four flaws in advisory SNWLID-2026-0017.
