Skip to content
SonicWall Patches SSRF Flaw in SMA1000 Appliances

SonicWall Patches SSRF Flaw in SMA1000 Appliances

First seen 7 Oct 2026, 14:27 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 7, 2026 at 14:28 UTC
  • •CVE-2026-102255 is a critical SSRF vulnerability in SMA1000 appliances.
  • •SonicWall has released hotfixes to address this flaw and three others.
  • •No active exploitation has been reported, but users are urged to patch immediately.

SonicWall has released hotfixes for a server-side request forgery (SSRF) vulnerability, CVE-2026-102255, affecting its SMA1000 series appliances. The flaw allows remote unauthenticated attackers to direct the appliance to issue requests on their behalf, potentially accessing internal functionality. The vulnerability affects models 6210, 7210, and 8200v running outdated firmware. SonicWall has not observed any of this flaw but has urged users to apply the patches immediately. Additionally, three other vulnerabilities were patched in the same advisory, including CVE-2026-102256, CVE-2026-102257, and CVE-2026-102258. The company has a history of zero-day exploits targeting SMA1000 appliances, making this patch a high priority for users. The hotfixes were made available on October 6, 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2025-01-23
CVE-2025-23006 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-14
CVE-2026-15409 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-14
CVE-2026-15410 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-01
CVE-2026-83548 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-01
CVE-2026-83549 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-06
SonicWall releases hotfixes
SonicWall issued hotfixes for CVE-2026-102255 and three other vulnerabilities affecting SMA1000 appliances.
Bleepingcomputer
2026-10-07
CVE-2026-102255 published
CVE-2026-102255, a critical SSRF vulnerability, was officially published with a CVSS score of 10.0.
Helpnetsecurity
2026-10-07
CVE-2026-102256, 102257, 102258 published
Three additional vulnerabilities were published alongside CVE-2026-102255, all addressed in the recent hotfix.
Helpnetsecurity
2026-10-07
CVE-2026-102257 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-07
CVE-2026-102258 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (4)

Following this threat?

Track Sou5, Sonicwall and CVE-2025-23006 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which SonicWall models are affected?
The affected models are SMA1000 series 6210, 7210, and 8200v.
What should I do if I use SMA1000 appliances?
You should apply the hotfixes released on October 6, 2026, to mitigate the vulnerabilities.
Is there any evidence of exploitation?
SonicWall has stated there is currently no evidence of exploitation in the wild for these vulnerabilities.