SonicWall Patches 4 SMA1000 Flaws, Including Critical Pre-Auth SSRF Rated CVSS 10

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


SonicWall has patched four vulnerabilities in its Secure Mobile Access (SMA) 1000 Series appliances, including a critical server-side request forgery (SSRF) flaw with a maximum CVSS score of 10.0.

The bug could let a remote attacker without valid credentials make the appliance send requests on their behalf, reach internal functions, and perform unauthorized operations.

The company published security advisory SNWLID-2026-0017 on October 6, 2026. SonicWall said it currently has no evidence that any of these four vulnerabilities are being exploited in the wild. However, it strongly advises affected customers to install the fixed software releases. The updates cover physical and virtual SMA 6210, SMA 7210, and SMA 8200v appliances.

Critical Pre-Authentication SSRF

Tracked as CVE-2026-102255, the most serious flaw affects the SMA1000 Appliance WorkPlace interface. It stems from an unintended alternate access path that allows the device to act as a forward proxy.

An attacker could abuse this path to make requests through the appliance rather than connect directly to protected internal functions.

This makes the issue especially concerning because the attacker does not need to sign in or persuade a user to take action. Its CVSS vector describes a network-accessible attack with low complexity and potentially high impact on confidentiality, integrity, and availability. SonicWall classifies it under CWE-918 for SSRF and CWE-441 for an unintended proxy, also called a confused deputy.

Additional Security Flaws

CVE-2026-102256 is a post-authentication command-injection vulnerability rated 7.8. Under specific conditions, an authenticated administrator could execute arbitrary operating-system commands, resulting in remote code execution. The advisory does not establish that this flaw can be chained with the critical SSRF issue.

CVE-2026-102257, rated 7.2, is a Zip Slip vulnerability in the Appliance Management Console (AMC). A specially crafted archive could cause files to be extracted outside the intended destination folder. SonicWall says this path-traversal issue can lead to remote code execution.

The fourth flaw, CVE-2026-102258, is stored cross-site scripting in AMC, with a CVSS score of 5.5. An authenticated administrator could, under specific conditions, store and potentially execute arbitrary JavaScript in the management console.

SonicWall credited Benoît Sevens of Anthropic with reporting the SSRF and command-injection flaws. Brian Mariani reported the Zip Slip issue through Trend Micro’s Zero Day Initiative, tracked as ZDI-CAN-28924, and received credit through DigitalCanion SA for the stored XSS vulnerability.

Affected Versions And Required Updates

Affected releases are 12.4.3-03526 and earlier, and 12.5.0-02952 and earlier. Customers should upgrade to platform-hotfix 12.4.3-03670 or later, or 12.5.0-03082 or later, depending on their software branch. SonicWall provides the latest hotfix through MySonicWall and lists no workaround for these vulnerabilities. The current fixes address all four issues across both affected firmware branches.

SSL-VPN services running on SonicWall firewalls and the SMA 100 Series product line are not affected. This distinction helps administrators identify the correct devices without treating every SonicWall VPN deployment as vulnerable to this advisory.

Cyber Security News previously covered separate SMA1000 vulnerabilities, CVE-2026-83548 and CVE-2026-83549, that SonicWall reported as actively exploited in September.

Those earlier fixes were 12.4.3-03526 and 12.5.0-02952, which are now listed as affected by this new advisory. Installing September’s update therefore does not resolve October’s newly disclosed flaws. Teams should check each appliance’s installed build against the latest fixed versions and complete the required upgrade, rather than rely on an earlier patch as proof that the device remains protected.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC

The post SonicWall Patches 4 SMA1000 Flaws, Including Critical Pre-Auth SSRF Rated CVSS 10 appeared first on Cyber Security News.