SonicWall warns of max severity SSRF flaw in SMA1000 gateways

A Critical Vulnerability Strikes Again: SonicWall Warns of SSRF Flaw in SMA1000 Gateways

SonicWall has just released hotfixes to address a maximum-severity server-side request forgery (SSRF) flaw in its SMA1000 series appliances. This vulnerability, tracked as CVE-2026-102255, could allow remote attackers without privileges to exploit the issue in low-complexity attacks and potentially gain unauthorized access to internal functionality.

The SSAF flaw affects the Appliance WorkPlace interface of SMA1000 6210, 7210, and 8200v models. While it’s good news that SonicWall has taken swift action by releasing hotfixes, this vulnerability highlights a worrying trend in the cybersecurity landscape. As we’ve seen before with other recent SonicWall vulnerabilities, attackers often target these flaws because they affect enterprise-grade secure remote access gateways used by government agencies, Managed Service Providers (MSSPs), and large corporations.

SonicWall has explained that the flaw stems from an unintended alternate access-path weakness, which can be exploited to direct the appliance to issue requests on behalf of the attacker. This could potentially allow unauthorized operations to be performed, even if the attacker doesn’t have privileges. While there is currently no evidence of active exploitation, SonicWall strongly advises users of SMA1000 series appliances to deploy hotfixes released on Tuesday to block potential attacks targeting their virtual or physical appliances.

The fact that over 400 Internet-exposed SMA1000 appliances are tracked by internet security threat watchdog Shadowserver makes this vulnerability even more pressing. As we’ve seen with previous SonicWall vulnerabilities, attackers often chain multiple exploits together to achieve their goals. This highlights the importance of staying up-to-date with security patches and keeping software and firmware current.

It’s worth noting that CISA has added 19 SonicWall vulnerabilities to its list of actively exploited flaws over the last four years, with 13 of those vulnerabilities also being abused in ransomware attacks. This emphasizes the need for organizations to take proactive measures to prevent such attacks from happening in the first place.

To protect themselves against this vulnerability, SonicWall customers are urged to upgrade to the mentioned fixed release version as soon as possible. For non-SonicWall users, this serves as a reminder of the importance of staying informed about vulnerabilities and keeping software and firmware up-to-date to prevent similar attacks. As always, vigilance is key in the ever-evolving cybersecurity landscape.


Source: Bleeping Computer — 2026-10-07