SonicWall SMA1000 CVE-2026-102255: Max-Severity SSRF — Patch Now
A pre-auth SSRF bug with a perfect 10.0 CVSS score lets unauthenticated attackers abuse SMA1000 WorkPlace portals. SonicWall's Oct. 6 hotfixes close it — here's what to patch.

SonicWall has patched a maximum-severity, pre-authentication Server-Side Request Forgery (SSRF) vulnerability in the SMA1000 Series Appliance WorkPlace portal. Tracked as CVE-2026-102255 and scored a perfect CVSS 10.0, the flaw lets a remote attacker with no credentials at all reach internal appliance functionality through an "unintended alternate access path" in the WorkPlace interface. SonicWall shipped hotfixes for it on October 6, 2026, alongside three lower-severity, authenticated bugs disclosed in the same advisory. The company says it has found no evidence any of the four flaws have been exploited in the wild — but given SMA1000's run of actively exploited zero-days over the past few months, administrators should not wait to apply the fix.
CVE-2026-102255 at a glance
- What: Pre-authentication SSRF in the SMA1000 Appliance WorkPlace interface (CWE-441 / CWE-918)
- CVSS: 10.0 Critical (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
- Affected: SMA1000 6210, 7210 and 8200v on firmware 12.4.3 (platform-hotfix 12.4.3-03526 and older) and 12.5.0 (platform-hotfix 12.5.0-02952 and older)
- Fixed in: 12.4.3-03670 and higher, or 12.5.0-03082 and higher
- Exploited? No evidence of in-the-wild exploitation, per SonicWall
- Advisory: SNWLID-2026-0017, published October 5, 2026
What happened: CVE-2026-102255 explained
SonicWall's advisory SNWLID-2026-0017 discloses four vulnerabilities in the SMA1000 Series. The headline issue, CVE-2026-102255, is a pre-authentication SSRF vulnerability in the SMA1000 Appliance WorkPlace interface. According to the National Vulnerability Database entry, the bug exists "due to an unintended alternate access path," and by abusing that path, "a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations."
In plain terms: the WorkPlace portal is the end-user-facing login page that SMA1000 appliances expose to remote workers. It's designed to be reachable without logging in first — that's the whole point of a login portal — but CVE-2026-102255 means an attacker can use that same unauthenticated entry point to trick the appliance into making network requests on the attacker's behalf. SSRF bugs like this are frequently used as a stepping stone to reach internal management interfaces, cloud metadata services, or other systems that should never be reachable from the public internet.
NVD classifies the flaw under two weakness types: CWE-918 (Server-Side Request Forgery) and CWE-441 (Unintended Proxy or Intermediary, sometimes called a "confused deputy" problem) — a pairing that reflects how the appliance itself becomes the unwitting tool an attacker uses to reach deeper into a network.
The WorkPlace interface exists so that remote employees can reach a clientless web portal, download the SMA connector software, or launch bookmarked internal applications before they've authenticated with a username and password — that's the entire reason it has to be reachable from the open internet in the first place. An SSRF flaw in exactly this component is particularly dangerous because organizations cannot simply firewall it off without breaking the remote-access service it was deployed to provide. That is also what separates CVE-2026-102255 from the three AMC-side bugs in the same advisory: AMC is an administrative console that security teams can and should restrict to a management network, while WorkPlace is designed, by necessity, to be internet-facing.
Why CVE-2026-102255 earned a perfect CVSS 10.0
A base score of 10.0 is reserved for the small number of flaws where every exploitability and impact metric maxes out. NVD's vector string for CVE-2026-102255 — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H — breaks down like this:
- Attack Vector: Network — exploitable remotely over the internet, no local or adjacent access needed
- Attack Complexity: Low — no special conditions or race windows required
- Privileges Required: None — this is the pre-authentication piece; no valid account is needed
- User Interaction: None — nothing for a victim or admin to click
- Scope: Changed — the exploited component can impact resources beyond its own security scope
- Confidentiality / Integrity / Availability: High / High / High — a successful exploit can fully compromise all three
That combination — zero privileges, zero complexity, full impact, reachable straight from the internet — is why this sits at the absolute top of the CVSS scale alongside flaws like the kind seen in other recent pre-authentication network-edge vulnerabilities that have drawn urgent patch guidance this year.
Who's affected: models and firmware versions
CVE-2026-102255 and the other three CVEs in SNWLID-2026-0017 affect the SonicWall SMA1000 Series specifically — the 6210, 7210 and 8200v models, across all supported hypervisor deployments. The affected firmware branches are 12.4.3 and 12.5.0.
| CVE | Vulnerability type | CVSS 3.1 | Access required | In-the-wild exploitation |
|---|---|---|---|---|
| CVE-2026-102255 | Server-Side Request Forgery (WorkPlace interface) | 10.0 Critical | None (pre-auth) | None observed |
| CVE-2026-102256 | OS Command Injection (remote code execution) | 7.8 High | Authenticated administrator | None observed |
| CVE-2026-102257 | Zip Slip path traversal (Appliance Management Console) | 7.2 High | Authenticated administrator | None observed |
| CVE-2026-102258 | Stored Cross-Site Scripting (Appliance Management Console) | 5.5 Medium | Authenticated administrator | None observed |
Affected builds, per SonicWall's own advisory, are 12.4.3 with platform-hotfix 12.4.3-03526 and older, and 12.5.0 with platform-hotfix 12.5.0-02952 and older. If your SMA1000 is running those or any earlier build, all four issues apply to your deployment.
The other three flaws in the same advisory
SNWLID-2026-0017 isn't a single-bug advisory. Three additional vulnerabilities, all requiring an authenticated administrator session on the Appliance Management Console (AMC) rather than anonymous network access, were patched in the same round of hotfixes:
- CVE-2026-102256 (CVSS 7.8): An OS command injection flaw that NVD describes as allowing "a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution." It requires an existing admin-level session, but the end result — arbitrary command execution — makes it serious for any environment where admin credentials are compromised through phishing or credential reuse.
- CVE-2026-102257 (CVSS 7.2): A classic Zip Slip path-traversal bug in the AMC interface. An attacker who can upload a specially crafted archive can extract files outside the intended destination directory, which can again lead to remote code execution.
- CVE-2026-102258 (CVSS 5.5): A stored cross-site scripting flaw in the AMC that could let an authenticated administrator store and potentially execute arbitrary JavaScript within the management console.
None of these three require the CVE-2026-102255 SSRF to be exploited first, and SonicWall's advisory treats them as a set unrelated to vulnerabilities reported on any other SonicWall product line. Full technical write-ups for all four issues are catalogued under the shared advisory on SonicWall's PSIRT vulnerability-detail page.
Is CVE-2026-102255 being exploited?
As of SonicWall's advisory, published October 5, 2026 and last updated October 6, 2026, the vendor states plainly: "There is no evidence that these vulnerabilities are being exploited in the wild." That applies to all four CVEs in the SNWLID-2026-0017 advisory, including the critical SSRF.
That is genuinely good news, and it's worth taking SonicWall's statement at face value rather than assuming the worst. But it is not a reason to delay patching. CVSS 10.0, pre-authentication, network-exploitable vulnerabilities in internet-facing remote access gateways are exactly the category of bug that attracts rapid reverse-engineering once a hotfix ships, because diffing the patched and unpatched binaries can reveal the exact request path an attacker needs to abuse. The absence of confirmed exploitation today says nothing about tomorrow.
Why it matters: SMA1000's recent exploited-flaw history
SonicWall's SMA1000 line has not been a stranger to active exploitation this year. Two related SSRF/command-injection pairs were added to the CISA Known Exploited Vulnerabilities (KEV) catalog in 2026: CVE-2026-15409 and CVE-2026-15410, added July 14, 2026, and CVE-2026-83548 and CVE-2026-83549, added September 2, 2026. Notably, CVE-2026-83548 and CVE-2026-15409 describe the same general flaw class as the current CVE-2026-102255 — a pre-authentication SSRF in the SMA1000 WorkPlace interface reachable through an unintended access path — while their companion bugs were authenticated OS command injection or code injection issues in the Appliance Management Console, mirroring the pairing seen again in this latest advisory.
That pattern matters for two reasons. First, it shows attackers have repeatedly targeted this exact combination — an unauthenticated SSRF foothold in WorkPlace paired with a post-auth code-execution bug in AMC — on this product line within the same year. Second, it means defenders should not treat "no evidence of exploitation yet" as a reason to deprioritize this patch; the same category of flaw on the same component has been weaponized twice already in 2026, as documented in SonicWall's own disclosure history and similar rapid-exploitation patterns seen in other recent enterprise software zero-days.
Important: this is not the SMA 100 Series or firewall SSL-VPN
A common point of confusion with SonicWall advisories is mixing up product lines. CVE-2026-102255 and the rest of SNWLID-2026-0017 affect only the SMA1000 Series hardware and virtual appliances (6210, 7210, 8200v). SonicWall's advisory does not list the separate SMA 100 Series (SMA 200/210/400/410/500v) as affected by these four CVEs, and it does not reference the SSL-VPN feature built into SonicWall's firewall appliances (the Gen 6/Gen 7 NSa/TZ/NSsp lines). If you run SMA 100 Series hardware or rely on firewall-based SSL-VPN rather than a dedicated SMA1000 gateway, this specific advisory does not apply to your deployment — though it's still worth confirming your own firmware against SonicWall's product notices directly, since SMA 100 and SMA1000 have each had separate advisories this year.
This distinction matters in practice, not just on paper: security teams running mixed SonicWall estates — some branch offices on firewall SSL-VPN, a head-office SMA1000 cluster for larger remote-access populations — have historically conflated advisories across the two product lines, the same way confusion sometimes arises between similarly-named flaws in other vendors' remote-access and file-sharing stacks, such as the authentication-bypass and critical file-read vulnerabilities disclosed this year in unrelated enterprise platforms. Check the model number on the chassis or the VM's product string, not just the word "SonicWall," before deciding this advisory is or isn't relevant to you.
How to patch: fixed firmware and upgrade steps
SonicWall's fix for all four vulnerabilities, including CVE-2026-102255, ships as a firmware hotfix rather than a configuration workaround — there is no mitigation that fully closes an unauthenticated SSRF in a login portal short of upgrading. According to SonicWall's advisory, the fixed builds are:
- 12.4.3-03670 and higher (for appliances on the 12.4.3 branch)
- 12.5.0-03082 and higher (for appliances on the 12.5.0 branch)
To remediate:
- Identify every SMA1000 6210, 7210 or 8200v instance in your environment, including any secondary/DR appliances and all hypervisor-based virtual deployments.
- Check the currently installed platform-hotfix version against the "affected" ranges above (12.4.3-03526 and older, or 12.5.0-02952 and older).
- Download and apply the latest available hotfix for your platform branch through your My SonicWall account, confirming the installed version meets or exceeds 12.4.3-03670 or 12.5.0-03082 after the upgrade.
- Restart or fail over per SonicWall's standard maintenance-window guidance, and verify WorkPlace portal and AMC accessibility post-patch.
- Review AMC administrator accounts and credentials while you're in there — since three of the four CVEs require only an authenticated admin session to exploit, tightening admin access (unique accounts, MFA, restricted source IPs for AMC) reduces exposure to those three even before every appliance is patched.
- SonicWall Product Notice: SMA 1000 Series affected by Multiple Vulnerabilities (SNWLID-2026-0017)sonicwall.com
- SonicWall PSIRT: SNWLID-2026-0017 vulnerability detailpsirt.global.sonicwall.com
- NVD: CVE-2026-102255nvd.nist.gov
- NVD: CVE-2026-102256nvd.nist.gov
- NVD: CVE-2026-102257nvd.nist.gov
- CISA Known Exploited Vulnerabilities Catalogcisa.gov
Internet-facing WorkPlace portals should also be reviewed against your organization's general exposure-management practice; SonicWall's advisory does not describe a viable network-level workaround for CVE-2026-102255 that avoids the need to patch, given that the whole point of the WorkPlace interface is to be reachable pre-authentication.
What to do next
If you operate any SonicWall SMA1000 6210, 7210 or 8200v appliance, treat this as an immediate patch action rather than something to schedule for next month's maintenance window. The combination of CVSS 10.0, zero required privileges, and a track record of exploited SSRF bugs on this exact product and interface earlier in 2026 is enough to justify emergency change-control, even with SonicWall reporting no current exploitation of CVE-2026-102255 itself.
Concretely: inventory your SMA1000 fleet today, confirm each appliance's platform-hotfix version against the 12.4.3-03670 / 12.5.0-03082 fixed baselines, patch anything below that line, and set a calendar reminder to re-check SonicWall's PSIRT advisories periodically — this is the third SMA1000 SSRF disclosure of 2026, and the pattern suggests it may not be the last. Organizations without a current My SonicWall support entitlement should contact SonicWall or their reseller promptly, since hotfixes are distributed through that portal.
Frequently asked questions
What is CVE-2026-102255?
CVE-2026-102255 is a pre-authentication Server-Side Request Forgery (SSRF) vulnerability in the WorkPlace interface of SonicWall's SMA1000 Series appliances. It carries a maximum CVSS 3.1 score of 10.0 because it requires no credentials, no user interaction, and can be triggered remotely over the network to let an attacker direct the appliance to make unauthorized requests and reach internal functionality.
Which SonicWall SMA1000 models and firmware versions are affected?
The SMA1000 6210, 7210 and 8200v models, on all supported hypervisor deployments, are affected when running firmware 12.4.3 with platform-hotfix 12.4.3-03526 or older, or firmware 12.5.0 with platform-hotfix 12.5.0-02952 or older, according to SonicWall's advisory SNWLID-2026-0017.
Is CVE-2026-102255 being actively exploited?
No. SonicWall states in its advisory that there is no evidence CVE-2026-102255, or the three other vulnerabilities disclosed alongside it, are being exploited in the wild as of the advisory's October 6, 2026 update.
What firmware fixes CVE-2026-102255?
SonicWall's advisory lists the fixed builds as 12.4.3-03670 and higher for the 12.4.3 branch, and 12.5.0-03082 and higher for the 12.5.0 branch. Administrators should confirm their installed platform-hotfix version meets or exceeds these before considering the appliance patched.
Does this advisory affect the SMA 100 Series or firewall SSL-VPN?
No. SonicWall's SNWLID-2026-0017 advisory lists only the SMA1000 Series (6210, 7210, 8200v) as affected. It does not list the separate SMA 100 Series appliances or the SSL-VPN feature built into SonicWall's firewall products.
What other vulnerabilities were patched in the same advisory?
The same advisory, SNWLID-2026-0017, also fixes CVE-2026-102256 (OS command injection, CVSS 7.8), CVE-2026-102257 (Zip Slip path traversal, CVSS 7.2), and CVE-2026-102258 (stored cross-site scripting, CVSS 5.5). All three require an authenticated administrator session on the Appliance Management Console, unlike the unauthenticated CVE-2026-102255.
Sources
Sana Qureshi runs the security and privacy desk. She reports on actively exploited vulnerabilities, vendor patches and data breaches, and covers the password managers, VPNs and authentication tools readers use to protect themselves. Her alerts cite vendor advisories, CISA and the CVE record directly.

