SonicWall SMA1000 CVE-2026-102255: Third Pre-Auth SSRF of 2026 Makes "Patched in September" Out of Date

SonicWall SMA1000 CVE-2026-102255: Third Pre-Auth SSRF of 2026 Makes "Patched in September" Out of Date

On 2026-10-06, SonicWall published advisory SNWLID-2026-0017. It fixes four vulnerabilities in SMA1000 Series appliances (models 6210, 7210 and 8200v). The most serious is CVE-2026-102255, a pre-authentication server-side request forgery (SSRF) in the Work Place interface. SonicWall scores it CVSS 10.0. It is the third pre-authentication SSRF disclosed in SMA1000 this year. The first two, in July and September, were exploited in the wild and are listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

What we know about exploitation so far. SonicWall says there is "currently no evidence any of the vulnerabilities addressed in this release are being exploited in the wild." CVE-2026-102255 is not in CISA KEV (catalog 2026.10.08, checked 2026-10-09 10:15 IDT). No public proof-of-concept is known. CISA's ADP SSVC entry rates it Exploitation "none", Automatable "yes", Technical impact "total".

Why it matters now. The newest affected builds are exactly the builds that fixed the September zero-days: 12.4.3-03526 and 12.5.0-02952. An appliance that was fully patched for September is vulnerable today. SonicWall lists no workaround. The only fix is upgrading to 12.4.3-03670 or 12.5.0-03082 or later.

Technical Information

SonicWall describes CVE-2026-102255 as a pre-authentication SSRF in the SMA1000 Appliance Work Place interface, caused by "an unintended alternate access path" (CWE-918, CWE-441). According to the vendor, a remote unauthenticated attacker could "direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations." SonicWall has not said which internal functions or services can be reached. It has also not said whether this flaw is related to, or gets around, the September CVE-2026-83548 fix. Both questions are still open.

Scoring note: The 10.0 score comes from SonicWall, published with a CVSS v3.0 vector (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). NVD published the record on 2026-10-07 and lists it as Awaiting Analysis. The only score NVD shows is SonicWall's CNA score. NVD has not published its own score.

The four CVEs in SNWLID-2026-0017

CVE Type (CWE) Authentication Vendor CVSS KEV
CVE-2026-102255 Pre-auth SSRF in Work Place (CWE-918, CWE-441) None 10.0 No
CVE-2026-102256 OS command injection (CWE-78) Administrator login required 7.8 No
CVE-2026-102257 Zip Slip path traversal in the Appliance Management Console (AMC) (CWE-22) Post-auth (PR:H) 7.2 No
CVE-2026-102258 Stored XSS in the AMC (CWE-79) Authenticated administrator 5.5* No

*CVE-2026-102258: SonicWall's advisory gives 5.5 (PR:H/UI:N/S:U/C:H/I:L/A:N). The CNA metric on NVD shows 6.1 with a different vector (PR:N/UI:R/S:C/C:L/I:L/A:N). We quote the vendor's 5.5 and point out the mismatch until NVD completes its analysis.

None of the four October CVEs is in KEV. SonicWall reports no evidence that any of them has been exploited.

2026 SMA1000 SSRF timeline

Date Event
2026-06-22 Earliest sign of compromise in one July-wave incident, according to Volexity's investigation.
2026-07-14 SonicWall publishes SNWLID-2026-0008: CVE-2026-15409 (Work Place SSRF, 10.0) and CVE-2026-15410 (post-auth code injection, 7.2). The vendor says it "investigated multiple cases indicating the active exploitation". Fixed in 12.4.3-03453 and 12.5.0-02835. CISA adds both CVEs to KEV the same day, with ransomware use marked Known.
2026-07-15 / 07-17 Rapid7 and Volexity publish analyses of the July exploitation, including indicators.
2026-09-01 SonicWall publishes SNWLID-2026-0016: CVE-2026-83548 (pre-auth SSRF, 10.0) and CVE-2026-83549 (post-auth OS command injection, 7.8). The vendor says it "investigated a case indicating the active exploitation". Fixed in 12.4.3-03526 and 12.5.0-02952.
2026-09-02 CISA adds CVE-2026-83548 and CVE-2026-83549 to KEV, with ransomware use marked Unknown.
2026-10-06 SonicWall publishes SNWLID-2026-0017 (CVE-2026-102255/-102256/-102257/-102258). No known exploitation. Fixed in 12.4.3-03670 and 12.5.0-03082. The September fix builds are now in the affected range.
2026-10-07 NVD publishes all four CVEs (Awaiting Analysis). CISA ADP SSVC rates CVE-2026-102255 Exploitation "none".
2026-10-09 10:15 IDT KEV catalog 2026.10.08 checked: CVE-2026-102255 is not listed.

The KEV ransomware flags apply only to the July and September CVEs listed above. No ransomware activity has been reported for CVE-2026-102255.

Affected Product Versions

Source: SonicWall SNWLID-2026-0017 (2026-10-06).

Product / branch Affected Fixed Notes
SMA1000 6210 / 7210 / 8200v, 12.4.3 branch 12.4.3-03526 (platform hotfix) and earlier 12.4.3-03670 (platform hotfix) and later 12.4.3-03526 was the September 2026 fix build
SMA1000 6210 / 7210 / 8200v, 12.5.0 branch 12.5.0-02952 (platform hotfix) and earlier 12.5.0-03082 (platform hotfix) and later 12.5.0-02952 was the September 2026 fix build
SMA 100 Series Not affected n/a Vendor note
SSL-VPN on SonicWall firewalls Not affected n/a Vendor note

The July 2026 fix builds (12.4.3-03453, 12.5.0-02835) and the September 2026 fix builds (12.4.3-03526, 12.5.0-02952) all fall inside the October affected range.

Workaround and Mitigation

There is no workaround. SonicWall lists the workaround as "None." The only fix is to install the platform hotfix from mysonicwall.com:

  • 12.4.3 branch: upgrade to 12.4.3-03670 or later.
  • 12.5.0 branch: upgrade to 12.5.0-03082 or later.

Check the installed build on every SMA1000 appliance. Do not assume an appliance that got the September fix is safe. It is not.

Rescana's additional recommendation (TPRM perspective). SNWLID-2026-0017 contains no instruction to check for compromise. The July and September advisories did. The following advice is ours, not SonicWall's. Because the July and September SSRFs were exploited in the wild, we recommend that organizations running SMA1000 confirm they checked for compromise after each of those waves before closing out this patch:

  • July wave (CVE-2026-15409/-15410): review logs against the indicators published by SonicWall (SNWLID-2026-0008), Rapid7 and Volexity.
  • September wave (CVE-2026-83548/-83549): SonicWall published no specific indicators. It told customers to contact SonicWall Technical Support for an IoC review. If indicators are found, it says to re-image or redeploy the appliance, change all passwords and reset TOTP (SNWLID-2026-0016).
  • Limit the Appliance Management Console (AMC) to trusted administrative networks, and check whether the Work Place portal needs to be reachable from the internet.

Indicators of Compromise

No indicators of compromise have been published for CVE-2026-102255 or the other October CVEs. SonicWall's advisory includes no IoCs and no compromise-check instruction. No public proof-of-concept is known.

For the earlier waves, which are relevant to the compromise checks above:

No MITRE ATT&CK techniques have been published for any of these CVEs, so none are listed here.

Why This Matters for Third-Party Risk

Third-party risk teams need to review vendors quickly without getting the facts wrong. This advisory is a good example of how a fast answer can be wrong. Many vendors, MSPs and service providers use SMA1000 as their remote-access gateway into customer networks. Before this advisory, "we patched for September" was the right answer from a supplier. Now it is out of date, because the September builds are affected.

For this advisory, an accurate review means asking each supplier that uses SMA1000 to show evidence, not just answer yes or no, on three points:

  1. Current build: every SMA1000 appliance is on 12.4.3-03670+ or 12.5.0-03082+.
  2. Exposure: whether the Work Place portal is reachable from the internet, and whether the AMC is limited to trusted administrative networks.
  3. Compromise checks: whether the supplier checked for compromise after the July and September 2026 waves, and re-imaged or rotated credentials and TOTP where needed.

Ask suppliers to confirm again if SonicWall updates the advisory or CVE-2026-102255 is added to KEV.

If you want to see how Rescana helps teams check vendor exposure to issues like this: Book a demo.

Forward this to your TPRM owner: If any of our vendors or MSPs use SonicWall SMA1000 for remote access, "patched for September" is no longer enough. Ask them for current build numbers (12.4.3-03670+ / 12.5.0-03082+), whether their portal is exposed to the internet, and whether they checked for compromise after the July and September waves.

Sources: SonicWall SNWLID-2026-0017, -0016 and -0008; NVD; CISA KEV catalog 2026.10.08; CISA ADP SSVC; Beazley Security Labs BSL-A1223; Rapid7; Volexity; Help Net Security; The Hacker News. KEV status is as of 2026-10-09 10:15 IDT.

Contact us / Book a demo

Talk to Rescana about this advisory, or book a demo of the platform.