Summaries
Short AI and tech summaries with source links, signal scores, and why each update matters for builders, founders, and Malaysian tech workers.
Showing 1-1 of 1 results
| Date | Provider | Score | Summary |
|---|---|---|---|
| 08 Oct 2026, 12:17 AM | The Hacker News | 3.0 | SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances
SonicWall released hotfixes for four flaws in SMA1000 appliances affecting models 6210, 7210 and 8200v. The most severe, CVE-2026-102255, is a pre-authentication SSRF in the WorkPlace portal rated CVSS 10.0; SonicWall says it has no evidence of exploitation. Fixed builds are 12.4.3-03670 and higher, and 12.5.0-03082 and higher, while 12.4.3-03526 and 12.5.0-02952 — the September 1 fixes for two previously exploited flaws — remain affected. The other three flaws require login: OS command injection RCE (CVSS 7.8, admin), Zip Slip RCE (CVSS 7.2, login), and stored XSS (CVSS 5.5, admin). Why: If your org or client runs SonicWall SMA1000 for remote access, the action is concrete: check the running build against 12.4.3-03670 / 12.5.0-03082 and install the MySonicWall hotfix, because no workaround is listed and the appliance restarts. If you do not run SMA1000, this likely requires no action beyond noting that the September 1 builds were not sufficient. |