VMTech
Discuss a project →

SonicWall releases SMA1000 hotfixes for critical WorkPlace SSRF

SonicWall releases SMA1000 hotfixes for critical WorkPlace SSRF

SonicWall has released hotfixes for four vulnerabilities in SMA1000 remote-access appliances, including CVE-2026-102255, a pre-authentication server-side request forgery flaw rated 10.0 on the CVSS scale. The issue affects the WorkPlace login portal on SMA1000 6210, 7210 and 8200v models.

CVE-2026-102255 could allow an attacker without credentials to send requests through the appliance, reach internal functionality and perform unauthorized operations. SonicWall said the issue stems from an unintended access path and did not identify the internal functions that could be reached. The company said it has no evidence that any of the four newly disclosed flaws is being exploited.

Fixed builds and affected releases

For the 12.4.3 platform branch, versions 12.4.3-03526 and earlier are affected; the fix is in 12.4.3-03670 and later. For the 12.5.0 branch, versions 12.5.0-02952 and earlier are affected; administrators need 12.5.0-03082 or later.

This detail is particularly important for teams that applied SonicWall’s September updates. The vendor had named 12.4.3-03526 and 12.5.0-02952 as fixes for vulnerabilities it reported as exploited at that time, but those builds remain affected by the new set of issues and require the latest hotfix.

  • CVE-2026-102255: pre-authentication SSRF in WorkPlace, CVSS 10.0.
  • CVE-2026-102256: OS command injection that could lead to remote code execution, requiring an administrator login, CVSS 7.8.
  • CVE-2026-102257: Zip Slip archive extraction issue in the Appliance Management Console, requiring login, CVSS 7.2.
  • CVE-2026-102258: stored cross-site scripting in the Appliance Management Console, requiring an administrator login, CVSS 5.5.

A recurring pre-authentication exposure

The latest disclosure is SonicWall’s third fix this year for a 10.0-rated, no-login SSRF issue in WorkPlace. In July, the company disclosed CVE-2026-15409 and CVE-2026-15410; in September, it disclosed CVE-2026-83548 and CVE-2026-83549. SonicWall said it had investigated exploitation in both earlier cases.

The wider pattern is reflected in SonicWall attacks among active security incidents where SonicWall attacks appeared among the week’s active security incidents. Rapid7 said the July SSRF issue could be used to open a tunnel to services available only inside the appliance, while the accompanying administrator-level flaw could be used to gain root access. SonicWall has not said whether CVE-2026-102255 can be chained with any of the three new authenticated vulnerabilities.

Operational response

Hotfixes are available through the MySonicWall portal, and the appliance restarts after installation. SonicWall lists no workaround. SSL-VPN on SonicWall firewalls and the SMA 100 Series are not affected.

Security and infrastructure teams should identify SMA1000 6210, 7210 and 8200v deployments, verify their installed platform-hotfix build, and plan the required restart before applying the fixed release. Because the most severe flaw is accessible before login, prompt version verification and controlled patch deployment are the practical business priority.

#cybersecurity#sonicwall#vulnerability#networksecurity
Open analytics
On the site 0 views
min read 3 07.10.2026
Instagram

SonicWall releases SMA1000 hotfixes for critical WorkPlace SSRF

Open the post on Instagram ↗