SonicWall patched four SMA1000 flaws on 7 October 2026. The worst, CVE-2026-102255, is a pre-authentication server-side request forgery scored CVSS 10. SonicWall says it has no evidence these four are being exploited. That is a patch window, not a reason to wait.
What happened
The bug is an unintended alternate path into the SMA1000 Work Place interface. A remote attacker who is not logged in can make the appliance send requests on their behalf, reach internal functions, and perform unauthorised operations. The same release also fixes CVE-2026-102256 (CVSS 7.8, authenticated admin command execution), CVE-2026-102257 (CVSS 7.2, path traversal to code execution), and CVE-2026-102258 (CVSS 5.5, stored script in the management console).
SMA 1000 models 6210, 7210, and 8200v on 12.4.3-03526, 12.5.0-02952, and earlier are affected. SSL-VPN on SonicWall firewalls, and the SMA 100 series, are not affected by this set.
Who is affected
Organisations and MSSPs that publish an SMA1000 Work Place portal to the internet. These appliances sit in front of remote access for mid-size and large estates, which is why a CVSS 10 SSRF here matters more than the same bug class on an internal app.
- SMA 1000 models 6210, 7210, and 8200v below the fixed builds
- Fixed builds: 12.5.0-03082 and 12.4.3-03670
- Not in scope: firewall SSL-VPN, and SMA 100 series
What to do now
Upgrade SMA1000 to 12.5.0-03082 or 12.4.3-03670 before this follows the last SMA1000 zero-day pattern. Hotfixes are on mysonicwall.com. Until the appliance is on a fixed build, keep the Work Place interface off the open internet. SonicWall's own note of no exploitation applies only to the flaws in this release.
Source: SecurityWeek, SonicWall and Splunk Patch Critical Vulnerabilities. Vendor detail: SonicWall SNWLID-2026-0017.
Also on the blog
- CVE-2026-21589: unauthenticated file read on 8 Atlassian products
- FortiBleed: FBI says 86,644 FortiGate devices still locked out
- tensorlake 0.5.144: npm worm steals cloud and AI-tool credentials
- Chrome 155 patches 247 flaws, four of them critical
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.