Vulnerabilities · 2h ago
The Dutch NCSC said SonicWall fixed four critical flaws in SMA1000, including pre-authentication server-side request forgery (SSRF) and post-authentication OS command-injection remote code execution, each rated CVSS 10.0 under CVE-2026-102258, CVE-2026-102257, CVE-2026-102255, and CVE-2026-102256. The appliance sits at the edge, so the issue lands on a trust boundary many teams use to keep internal services off the internet.
The SSRF bug lets an unauthenticated outsider make the appliance send internal requests on their behalf, which means the gateway can become the path into back-end services instead of the barrier in front of them. The command-injection flaw then extends that risk to the management plane: once authenticated, an attacker can run operating-system commands on the appliance itself.
For organizations that use SMA1000 as an internet-facing remote-access gateway, the lasting exposure is not just the box but whatever internal endpoints it can reach and vouch for. The advisory does not report active exploitation, but it does show that both perimeter trust and local administration are in scope here.
6 sources covering this story
SonicWall warns of max severity SSRF flaw in SMA1000 gateways
SonicWall has released hotfixes to address a maximum-severity server-side request forgery (SSRF) flaw in SMA1000 series appliances.
SonicWall fixes pre-auth SSRF flaw in SMA 1000 appliances (CVE-2026-102255) - Help Net Security
CVE-2026-102255 could allow remote unauthenticated attackers to direct a SMA 1000 appliance to issue requests on their behalf.
Risolte vulnerabilità in prodotti SonicWall
SonicWall ha rilasciato aggiornamenti di sicurezza per sanare 4 vulnerabilità, di cui 1 con gravità "critica" e 2 con gravità "alta", che interessano i modelli 6210, 7210 e 8200v appartenenti alla serie SMA1000.
Múltiples vulnerabilidades en SMA 1000 de SonicWall
SonicWall ha publicado 4 vulnerabilidades: una de severidad crítica, 2 de severidad alta y una de seve
Kwetsbaarheden verholpen in SonicWall SMA1000 Appliance
SonicWall heeft meerdere kwetsbaarheden verholpen in de SonicWall SMA1000 Appliance.
SonicWall SMA1000 Series Appliances Affected By Multiple Vulnerabilities
1) CVE-2026-102255 - Pre-authentication SSRF via unintended forward-proxy A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access p
Part of the PlainSec briefing for 2026-10-07