Vulnerabilities · 2h ago

SonicWall SMA1000 Flaws Punch Through the Gateway

The Dutch NCSC said SonicWall fixed four critical flaws in SMA1000, including pre-authentication server-side request forgery (SSRF) and post-authentication OS command-injection remote code execution, each rated CVSS 10.0 under CVE-2026-102258, CVE-2026-102257, CVE-2026-102255, and CVE-2026-102256. The appliance sits at the edge, so the issue lands on a trust boundary many teams use to keep internal services off the internet.

The SSRF bug lets an unauthenticated outsider make the appliance send internal requests on their behalf, which means the gateway can become the path into back-end services instead of the barrier in front of them. The command-injection flaw then extends that risk to the management plane: once authenticated, an attacker can run operating-system commands on the appliance itself.

For organizations that use SMA1000 as an internet-facing remote-access gateway, the lasting exposure is not just the box but whatever internal endpoints it can reach and vouch for. The advisory does not report active exploitation, but it does show that both perimeter trust and local administration are in scope here.

CVE-2026-102258

NVD KEV

CVE-2026-102257

NVD KEV

CVE-2026-102255

NVD KEV

CVE-2026-102256

NVD KEV

Timeline

Sources

6 sources covering this story

Entities

Vendor digest: SonicWall

Part of the PlainSec briefing for 2026-10-07

Editions

Related stories