SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances
- ID
- 32901
- Status
- summarized
- Published
- 08 Oct 2026, 12:17 AM
- Fetched
- 08 Oct 2026, 2:58 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/10/sonicwall-patches-cvss-100-pre.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 3.0
- Created
- 08 Oct 2026, 2:59 AM
- Tags
- Audience
- developerssaas_startup_founders
What happened
SonicWall released hotfixes for four flaws in SMA1000 appliances affecting models 6210, 7210 and 8200v. The most severe, CVE-2026-102255, is a pre-authentication SSRF in the WorkPlace portal rated CVSS 10.0; SonicWall says it has no evidence of exploitation. Fixed builds are 12.4.3-03670 and higher, and 12.5.0-03082 and higher, while 12.4.3-03526 and 12.5.0-02952 — the September 1 fixes for two previously exploited flaws — remain affected. The other three flaws require login: OS command injection RCE (CVSS 7.8, admin), Zip Slip RCE (CVSS 7.2, login), and stored XSS (CVSS 5.5, admin).
Why it matters
If your org or client runs SonicWall SMA1000 for remote access, the action is concrete: check the running build against 12.4.3-03670 / 12.5.0-03082 and install the MySonicWall hotfix, because no workaround is listed and the appliance restarts. If you do not run SMA1000, this likely requires no action beyond noting that the September 1 builds were not sufficient.
Discussion angle
Ask who owns patching for remote-access appliances: if SMA1000 is in scope, compare your build to 12.4.3-03670 / 12.5.0-03082 and plan the restart; if not, treat this as a quick inventory prompt rather than a general panic.