[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fbRt2vuGIqRJBTHJR687WaW3Kixd28B15j2yUv4n8JpA":3},{"article":4,"iocs":46},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":33,"category":34,"article_tags":38},"6a8d1bfc-125a-415a-9fa7-e973c7e8cd95","SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances","sonicwall-patches-cvss-10-0-pre-authentication-ssrf-flaw-in-sma1000-appliances-6e23ba","SonicWall has released hotfixes for four flaws in its SMA1000 appliances, the gateways that give remote workers access to a company's network and applications. The most serious could allow an attacker without a login to send requests through the appliance and reach internal functions. SonicWall rates it 10.0 on the CVSS scale and says it has no evidence that any of the four flaws is being","SonicWall has released critical hotfixes for four vulnerabilities affecting its SMA1000 appliances, which provide remote access to corporate networks. The most severe, CVE-2026-102255, is a pre-authentication Server-Side Request Forgery (SSRF) flaw with a CVSS score of 10.0, allowing unauthenticated attackers to access internal functions. While SonicWall has no evidence of exploitation for these specific flaws, this marks the third time this year they've addressed a critical SSRF vulnerability in the SMA1000's WorkPlace portal.","SonicWall patches critical CVSS 10.0 SSRF vulnerability in SMA1000 appliances.","SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances Swati KhandelwalOct 07, 2026Vulnerability \u002F Network Security SonicWall has released hotfixes for four flaws in its SMA1000 appliances, the gateways that give remote workers access to a company's network and applications. The most serious could allow an attacker without a login to send requests through the appliance and reach internal functions. SonicWall rates it 10.0 on the CVSS scale and says it has no evidence that any of the four flaws is being used in attacks. The most serious flaw, tracked as CVE-2026-102255, is a server-side request forgery (SSRF) bug in WorkPlace, the portal that SMA1000 users log in to. It exists due to an unintended access path through SonicWall and can be reached before authentication. An attacker who abuses that path could \"reach internal functionality and perform unauthorized operations,\" SonicWall said in its security advisory, dated October 6, without saying which functions. All four flaws affect SMA1000 models 6210, 7210 and 8200v on these platform-hotfix versions: Version 12.4.3: 12.4.3-03526 and older versions are affected. 12.4.3-03670 and higher versions are fixed. Version 12.5.0: 12.5.0-02952 and older versions are affected. 12.5.0-03082 and higher versions are fixed. The affected versions include 12.4.3-03526 and 12.5.0-02952, which SonicWall named on September 1 as the fix for two flaws it reported as exploited. An appliance still on those versions needs the new hotfix. SSL-VPN on SonicWall firewalls and the SMA 100 Series are not affected. The hotfix is available from the MySonicWall portal, and the appliance restarts when the installation finishes. No workaround is listed. The other three flaws can be used only after logging in. Two of them are in the Appliance Management Console (AMC), where administrators configure the appliance. CVE Flaw Where Access needed SonicWall CVSS score CVE-2026-102255 Server-side request forgery (SSRF) WorkPlace None 10.0 CVE-2026-102256 OS command injection that could lead to remote code execution SMA1000 appliance, component not named Administrator login 7.8 CVE-2026-102257 Zip Slip: an attacker can use a specially made archive to extract files outside the intended folder, which could lead to remote code execution AMC Login 7.2 CVE-2026-102258 Stored cross-site scripting (XSS) AMC Administrator login 5.5 It is the third time this year that SonicWall has fixed a 10.0-rated SSRF flaw in WorkPlace that needs no login. SonicWall disclosed CVE-2026-15409 and CVE-2026-15410 on July 14, and CVE-2026-83548 and CVE-2026-83549 on September 1. Both times, it said it had investigated attacks exploiting the flaws: \"multiple cases\" in July and \"a case\" in September. Each pair consisted of an SSRF flaw that required no login and a second flaw that could allow a logged-in administrator to run commands on the appliance. SonicWall's own staff found both of those pairs. SonicWall credited outside researchers for the four new flaws: Benoît Sevens of Anthropic for CVE-2026-102255 and CVE-2026-102256, and Brian Mariani of DigitalCanion SA for the other two, one of them reported through Trend Micro's Zero Day Initiative. In the July attacks, CVE-2026-15409 allowed an attacker with no login to open a tunnel to services that respond only inside the appliance, according to Rapid7. The attacker could then run commands and use CVE-2026-15410 to gain root access, which is full control of the appliance. SonicWall has not said whether the new SSRF flaw can be combined with the other three in the same way. In its July and September advisories, SonicWall told customers to check their appliances for indicators of compromise and, if any were found, to re-image or redeploy the appliance, change user and administrator passwords, and reset the TOTP tokens used for one-time login codes. It has given no such instruction for the four new flaws. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  network security, SonicWall, Vulnerability, Web Security ⚡ Top Stories This Week ⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members How Financial Services Companies Can Modernize Their Software Supply Chain US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access Zero Trust for AI Agents Starts With Fixing Zero Visibility ⭐ Featured Resources Discover Hidden AI Agents and Lock Down Their Access — Get a Demo The CISO Playbook for Board-Ready Security Reporting The Browser Attacks Your Security Stack Is Missing 41 Cybersecurity Courses. One Week to Level Up Your Skills","https:\u002F\u002Fthehackernews.com\u002F2026\u002F10\u002Fsonicwall-patches-cvss-100-pre.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEg93cv3mDcrVCz0IYIpCH3eRNzbDYkM2Z_N2acg9D6bCFGvE3cr3eJ1uGJblGasKplvyvuO6pSuMCxamTwHJSP2ztJ7WBswe1igBdzoadRJPZSDfs5K2og83_iMDMZYuh-LpFdA4qb4Pv7SyJ1A4EQtO_gi6nuxV5ioid32rXABiS0Il9t8boUATp2lTes\u002Fs1600\u002Fsonicwall.png","2026-10-07T16:17:44+00:00","2026-10-07T18:00:14.350745+00:00",9,[18,21,24,27,29,31],{"name":19,"type":20},"SMA1000","product",{"name":22,"type":23},"SonicWall","vendor",{"name":25,"type":26},"SSRF","technology",{"name":28,"type":26},"OS command injection",{"name":30,"type":26},"Zip Slip",{"name":32,"type":26},"XSS","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":33,"icon":35,"name":36,"slug":37},null,"Vulnerabilities","vulnerabilities",[39,41],{"category":40},{"id":33,"icon":35,"name":36,"slug":37},{"category":42},{"id":43,"icon":35,"name":44,"slug":45},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[47,51,54,57,60,63,66,68],{"type":48,"value":49,"context":50},"cve","CVE-2026-102255","Critical SSRF vulnerability in SMA1000 WorkPlace portal.",{"type":48,"value":52,"context":53},"CVE-2026-102256","OS command injection vulnerability in SMA1000 appliance.",{"type":48,"value":55,"context":56},"CVE-2026-102257","Zip Slip vulnerability in SMA1000 Appliance Management Console (AMC).",{"type":48,"value":58,"context":59},"CVE-2026-102258","Stored XSS vulnerability in SMA1000 Appliance Management Console (AMC).",{"type":48,"value":61,"context":62},"CVE-2026-15409","Previously exploited SSRF vulnerability in SMA1000 WorkPlace portal.",{"type":48,"value":64,"context":65},"CVE-2026-15410","Previously exploited command injection vulnerability in SMA1000 appliance.",{"type":48,"value":67,"context":62},"CVE-2026-83548",{"type":48,"value":69,"context":65},"CVE-2026-83549"]