HomeSecuritySonicWall: Critical vulnerability in SMA1000 devices

SonicWall: Critical vulnerability in SMA1000 devices

SonicWall has released security patches for a critical Server-Side Request Forgery (SSRF) vulnerability affecting certain SMA1000 series appliances . The vulnerability, which is listed as CVE-2026-102255 , is considered particularly serious because it could allow remote attackers to interact with the internal functions of a vulnerable appliance.

SonicWall: Critical vulnerability in SMA1000 devices

The company urges administrators of affected systems to immediately install the available updates, although so far there are no indications that this vulnerability has been exploited in actual attacks.

Which systems are affected?

CVE-2026-102255 was found in the Appliance WorkPlace of specific models of the SMA1000 family. Specifically, it affects the SMA1000 6210, SMA1000 7210, and SMA1000 8200v.

See also: FBI warns: FortiBleed Threat remains active

SonicWall clarifies that the issue does not affect the SMA 100, nor does it affect the SSL-VPN provided by the company's firewalls. This distinction is important for organizations using different SonicWall platforms, as not all installations require the same actions.

How the vulnerability can be exploited

The issue is related to an unintended alternate access route, which can be exploited by a remote attacker without prior privileges or account on the system. The attack is characterized as low complexity, theoretically increasing the risk for devices accessible via the Internet.

In an SSRF attack, the attacker attempts to make a vulnerable service make requests to other destinations on their behalf. In the case of the SMA1000, this could allow access to internal device functions and perform actions that should not be available to an unauthorized user.

SonicWall warns that an unauthenticated remote attacker could, under certain circumstances, exploit this path to direct the device to execute requests on their behalf.

SonicWall: Critical vulnerability in SMA1000 devices

More than 400 devices on display

The issue is exacerbated by the nature of the SMA1000. These devices are used as gateways for secure remote access to corporate networks and applications, making them a particularly attractive target for cybercriminals.

Shadowserver data shows that more than 400 SMA1000 devices are currently visible on the Internet. This number does not necessarily mean that all of them remain vulnerable, as some of them may have already been updated.

However, Internet exposure increases the need for immediate response, particularly in organizations where devices act as entry points to critical infrastructure.

See also: WordPress: Critical vulnerabilities in Ninja Forms and WPC Product Bundles for WooCommerce

The SMA1000 has been repeatedly targeted

The new vulnerability does not appear in a security hole, but in a period in which SMA1000 devices have been repeatedly attacked. Since the beginning of the year, there have been several cases where security holes were exploited before or shortly after the relevant fixes were released.

In July, CVE-2026-15409 and CVE-2026-15410 were used in attacks to install the Sou5, OrangeTail, and RootRun malware on vulnerable VPN devices. The US CISA linked the activity to ransomware groups.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Even more recently, SonicWall had warned about CVE-2026-83548 and CVE-2026-83549, which could be combined to achieve remote code execution on vulnerable SMA1000 devices.

Why immediate information is critical

The fact that no active exploit for CVE-2026-102255 has been identified so far does not mean that the risk can be ignored. Devices that act as remote access gateways have always been attractive targets, as a successful breach can give attackers access to much wider corporate environments.

See also: Critical vulnerability in Atlassian exposes eight products

SonicWall: Critical vulnerability in SMA1000 devices

CISA has already listed 19 SonicWall vulnerabilities on its list of actively exploited vulnerabilities over the past four years, with 13 of them being linked to ransomware incidents.

For organizations using the affected SMA1000 models, the priority is therefore clear: install the patch, scan devices exposed to the Internet, and review logs for suspicious activity. In infrastructures used for remote access, timely application of a hotfix can prove critical before a new vulnerability turns from a theoretical risk into a real security incident.

source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS