Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Hikvision Camera Vulnerability CVE-2021-36260 Targeted by Attackers
October 8, 2026
Fake Firefox Wallet Extensions Steal Crypto Recovery Phrases
October 8, 2026
Critical Tensorlake npm Package Flaw Spreads Shai-Hulud Worm, Steals Dev Secrets
October 8, 2026
Home/CyberSecurity News/SonicWall Patches Critical Pre-Auth SSRF (CVE-2024-XXXX) in SMA1000
CyberSecurity News

SonicWall Patches Critical Pre-Auth SSRF (CVE-2024-XXXX) in SMA1000

Key Takeaways SonicWall has released patches for four vulnerabilities affecting its SMA 1000 Series appliances. The most critical flaw, CVE-2026-102255, is a pre-authentication SSRF with a CVSS score...

Emy Elsamnoudy
Emy Elsamnoudy
October 7, 2026 3 Min Read
20 0

Key Takeaways

  • SonicWall has released patches for four vulnerabilities affecting its SMA 1000 Series appliances.
  • The most critical flaw, CVE-2026-102255, is a pre-authentication SSRF with a CVSS score of 10.0.
  • This critical vulnerability could enable unauthorized remote attackers to access internal network functions.
  • Affected organizations must update their SMA 6210, SMA 7210, and SMA 8200v appliances immediately.

SonicWall has issued a series of patches addressing four security vulnerabilities within its Secure Mobile Access (SMA) 1000 Series appliances. Among these, a severe server-side request forgery (SSRF) flaw, identified as CVE-2026-102255, carries the highest possible CVSS score of 10.0, indicating extreme criticality.

Table Of Content

  • Key Takeaways
  • Critical Pre-Authentication SSRF Uncovered
  • Additional Security Flaws Identified
  • Affected Versions and Required Updates
  • What You Should Do

This critical defect could permit an unauthenticated remote attacker to compel the appliance into initiating requests on their behalf, thereby gaining access to internal functions and potentially executing unauthorized operations.

The vendor released security advisory SNWLID-2026-0017 on October 6, 2026. While SonicWall states there is currently no evidence of these vulnerabilities being exploited in the wild, it strongly urges all customers using affected SMA 6210, SMA 7210, and SMA 8200v physical and virtual appliances to implement the provided software updates without delay.

Critical Pre-Authentication SSRF Uncovered

The most severe vulnerability, CVE-2026-102255, impacts the SMA1000 Appliance WorkPlace interface. This flaw originates from an unintended alternative access pathway that effectively transforms the device into a forward proxy. Threat actors could exploit this path to route requests through the appliance, circumventing direct connections to otherwise protected internal network functions.

The severity of this issue is amplified by its pre-authentication nature, meaning attackers do not require valid credentials or user interaction to exploit it. The associated CVSS vector highlights a network-accessible attack with low complexity, capable of significantly impacting confidentiality, integrity, and availability. SonicWall categorizes this vulnerability under CWE-918 for SSRF and CWE-441, which describes an unintended proxy or “confused deputy” scenario.

Additional Security Flaws Identified

Beyond the critical SSRF, three other vulnerabilities were addressed:

  • CVE-2026-102256: Post-Authentication Command Injection (CVSS 7.8)
    This flaw could allow an authenticated administrator, under specific conditions, to execute arbitrary operating-system commands, potentially leading to remote code execution. SonicWall’s advisory does not indicate a possible chain with the critical SSRF vulnerability.
  • CVE-2026-102257: Zip Slip Vulnerability (CVSS 7.2)
    Affecting the Appliance Management Console (AMC), this Zip Slip vulnerability could enable path traversal. A specially crafted archive might cause files to be extracted outside their intended directories, potentially leading to remote code execution.
  • CVE-2026-102258: Stored Cross-Site Scripting (CVSS 5.5)
    Also found in the AMC, this stored XSS vulnerability could allow an authenticated administrator, under certain conditions, to inject and execute arbitrary JavaScript within the management console.

SonicWall acknowledged Benoît Sevens of Anthropic for reporting the SSRF and command injection vulnerabilities. Brian Mariani, reporting through Trend Micro’s Zero Day Initiative (ZDI-CAN-28924), was credited for the Zip Slip issue, and DigitalCanion SA was recognized for the stored XSS vulnerability.

Affected Versions and Required Updates

The vulnerabilities impact SMA 1000 Series appliances running firmware versions 12.4.3-03526 and earlier, as well as 12.5.0-02952 and earlier. Customers must upgrade their appliances to platform hotfix 12.4.3-03670 or later, or 12.5.0-03082 or later, depending on their current software branch. These updates are available via MySonicWall. SonicWall has not provided any workarounds for these issues, emphasizing the need for direct patching.

It is important to note that SSL-VPN services operating on SonicWall firewalls and the SMA 100 Series product line are not affected by this advisory. This distinction is crucial for administrators to accurately scope their patching efforts.

Previously, in September, SonicWall addressed other SMA1000 vulnerabilities (CVE-2026-83548 and CVE-2026-83549) that were actively exploited. The patches for those issues, 12.4.3-03526 and 12.5.0-02952, are now themselves listed as vulnerable to this new set of flaws. Therefore, installing the September updates does not confer protection against the newly disclosed October vulnerabilities. Organizations must verify each appliance’s installed build against the latest fixed versions and perform the necessary upgrades, rather than assuming prior patches provide comprehensive security.

What You Should Do

  • Immediately identify all SonicWall SMA 1000 Series appliances (SMA 6210, SMA 7210, and SMA 8200v) within your environment.
  • Verify the current firmware version of each appliance. If running 12.4.3-03526 or earlier, or 12.5.0-02952 or earlier, an upgrade is mandatory.
  • Download and apply the latest hotfixes: 12.4.3-03670 or later, or 12.5.0-03082 or later, from MySonicWall.
  • Do not rely on previous updates as a substitute for applying these new patches. Confirm the specific build number post-update.
  • Monitor SonicWall’s security advisories for any further updates or emerging threats.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerability

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Hackers Breach South Korean Churches, Exposing 1 Million Members’ Data

Next Post

CrowdStrike, AWS, NVIDIA Expand Cybersecurity Startup Accelerator

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Hackers Hide C2 on Blockchain via Negative Hotel Review Malware
October 8, 2026
Critical Sungrow Inverter Vulnerability Lets Attackers Access Solar Plants
October 8, 2026
Critical LMCache Flaw (CVE-2024-XXXX) Gets PoC, Enables RCE
October 8, 2026
Top Authors
David kimber
David kimber
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us