Bleepingcomputer SonicWall Patches SSRF Flaw in SMA1000 Appliances
Article Content
- •CVE-2026-102255 is a critical SSRF vulnerability in SMA1000 appliances.
- •SonicWall has released hotfixes to address this flaw and three others.
- •No active exploitation has been reported, but users are urged to patch immediately.
SonicWall has released hotfixes for a server-side request forgery (SSRF) vulnerability, CVE-2026-102255, affecting its SMA1000 series appliances. The flaw allows remote unauthenticated attackers to direct the appliance to issue requests on their behalf, potentially accessing internal functionality. The vulnerability affects models 6210, 7210, and 8200v running outdated firmware. SonicWall has not observed any of this flaw but has urged users to apply the patches immediately. Additionally, three other vulnerabilities were patched in the same advisory, including CVE-2026-102256, CVE-2026-102257, and CVE-2026-102258. The company has a history of zero-day exploits targeting SMA1000 appliances, making this patch a high priority for users. The hotfixes were made available on October 6, 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Sou5, Sonicwall and CVE-2025-23006 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which SonicWall models are affected?
What should I do if I use SMA1000 appliances?
Is there any evidence of exploitation?
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…