SonicWall has released security patches for a critical Server-Side Request Forgery (SSRF) vulnerability affecting certain SMA1000 series appliances . The vulnerability, which is listed as CVE-2026-102255 , is considered particularly serious because it could allow remote attackers to interact with the internal functions of a vulnerable appliance.

The company urges administrators of affected systems to immediately install the available updates, although so far there are no indications that this vulnerability has been exploited in actual attacks.
Which systems are affected?
CVE-2026-102255 was found in the Appliance WorkPlace of specific models of the SMA1000 family. Specifically, it affects the SMA1000 6210, SMA1000 7210, and SMA1000 8200v.
See also: FBI warns: FortiBleed Threat remains active
SonicWall clarifies that the issue does not affect the SMA 100, nor does it affect the SSL-VPN provided by the company's firewalls. This distinction is important for organizations using different SonicWall platforms, as not all installations require the same actions.
How the vulnerability can be exploited
The issue is related to an unintended alternate access route, which can be exploited by a remote attacker without prior privileges or account on the system. The attack is characterized as low complexity, theoretically increasing the risk for devices accessible via the Internet.
In an SSRF attack, the attacker attempts to make a vulnerable service make requests to other destinations on their behalf. In the case of the SMA1000, this could allow access to internal device functions and perform actions that should not be available to an unauthorized user.
SonicWall warns that an unauthenticated remote attacker could, under certain circumstances, exploit this path to direct the device to execute requests on their behalf.

More than 400 devices on display
The issue is exacerbated by the nature of the SMA1000. These devices are used as gateways for secure remote access to corporate networks and applications, making them a particularly attractive target for cybercriminals.
Shadowserver data shows that more than 400 SMA1000 devices are currently visible on the Internet. This number does not necessarily mean that all of them remain vulnerable, as some of them may have already been updated.
However, Internet exposure increases the need for immediate response, particularly in organizations where devices act as entry points to critical infrastructure.
See also: WordPress: Critical vulnerabilities in Ninja Forms and WPC Product Bundles for WooCommerce
The SMA1000 has been repeatedly targeted
The new vulnerability does not appear in a security hole, but in a period in which SMA1000 devices have been repeatedly attacked. Since the beginning of the year, there have been several cases where security holes were exploited before or shortly after the relevant fixes were released.
In July, CVE-2026-15409 and CVE-2026-15410 were used in attacks to install the Sou5, OrangeTail, and RootRun malware on vulnerable VPN devices. The US CISA linked the activity to ransomware groups.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Even more recently, SonicWall had warned about CVE-2026-83548 and CVE-2026-83549, which could be combined to achieve remote code execution on vulnerable SMA1000 devices.
Why immediate information is critical
The fact that no active exploit for CVE-2026-102255 has been identified so far does not mean that the risk can be ignored. Devices that act as remote access gateways have always been attractive targets, as a successful breach can give attackers access to much wider corporate environments.
See also: Critical vulnerability in Atlassian exposes eight products

CISA has already listed 19 SonicWall vulnerabilities on its list of actively exploited vulnerabilities over the past four years, with 13 of them being linked to ransomware incidents.
For organizations using the affected SMA1000 models, the priority is therefore clear: install the patch, scan devices exposed to the Internet, and review logs for suspicious activity. In infrastructures used for remote access, timely application of a hotfix can prove critical before a new vulnerability turns from a theoretical risk into a real security incident.
source: www.bleepingcomputer.com
