SonicWall has released security updates for four vulnerabilities affecting its Secure Mobile Access (SMA) 1000 Series appliances. One of the flaws is considered critical and has received the maximum CVSS score of 10.0.
The most serious issue is a pre-authentication server-side request forgery (SSRF) vulnerability that could allow a remote attacker to send requests through a vulnerable appliance without logging in.
SonicWall published the security advisory on October 6, 2026. The company said it has not found evidence that these vulnerabilities are currently being exploited in attacks, but recommends that customers install the available updates as soon as possible.
The affected products include physical and virtual SMA 6210, SMA 7210, and SMA 8200v appliances.
Critical SSRF Vulnerability
The most serious vulnerability is CVE-2026-102255, which affects the SMA1000 Appliance WorkPlace interface.
The flaw is caused by an unintended access path that can make the appliance operate like a proxy. An attacker could abuse this behavior to send requests through the device and potentially reach internal services that should not be directly accessible.
The attack does not require valid credentials or user interaction, making the vulnerability particularly serious.
SonicWall has classified the issue under CWE-918 (SSRF) and CWE-441 (confused deputy/unintended proxy). The vulnerability can potentially affect the confidentiality, integrity, and availability of the affected system.
Three More Vulnerabilities
SonicWall also fixed three additional security issues:
- CVE-2026-102256 – Command Injection: Rated CVSS 7.8. An authenticated administrator could potentially execute operating-system commands under specific conditions, which could result in remote code execution.
- CVE-2026-102257 – Zip Slip: Rated CVSS 7.2. A specially crafted archive could extract files outside the intended directory. SonicWall says successful exploitation could potentially lead to remote code execution.
- CVE-2026-102258 – Stored XSS: Rated CVSS 5.5. An authenticated administrator could potentially store malicious JavaScript in the Appliance Management Console (AMC), where it could later execute in another user’s browser context.
The vulnerabilities were reported by security researchers from Anthropic, Trend Micro’s Zero Day Initiative, and DigitalCanion SA.
Affected Versions and Updates
SonicWall says the affected versions include:
- 12.4.3-03526 and earlier
- 12.5.0-02952 and earlier
Customers should upgrade to:
- 12.4.3-03670 or later
- 12.5.0-03082 or later
The required fixes are available through MySonicWall. SonicWall has not provided a workaround and recommends applying the appropriate hotfix.
It is important to note that SonicWall firewalls running SSL-VPN services and the SMA 100 Series are not affected by this particular advisory.
Administrators should check the exact software build running on each SMA1000 appliance and upgrade to a fixed version. Installing an earlier September update is not enough because the versions that contained those previous fixes are also affected by the newly disclosed vulnerabilities.
The key takeaway is simple: SMA1000 administrators should verify their appliance versions and apply the latest security updates as soon as possible.