Vulnerability
Published 2026-10-06
Verified 2026-10-07

SonicWall SMA1000 advisory SNWLID-2026-0017 (6 Oct): unauthenticated SSRF in Appliance WorkPlace rated CVSS 10.0 (CVE-2026-102255), plus admin command injection, a Zip Slip and stored XSS in the management console; September's zero-day fix builds are now listed as affected

SonicWall published advisory SNWLID-2026-0017 on 6 October 2026 covering four flaws in Secure Mobile Access (SMA) 1000 series appliances, physical and virtual SMA 6210, 7210 and 8200v. The worst, CVE-2026-102255 (CVSS 10.0), sits in the Appliance WorkPlace interface: an unintended alternate access path lets the appliance act as a forward proxy, so a remote attacker with no login can make it send requests on their behalf, reach internal functions and perform unauthorised operations (CWE-918 server-side request forgery and CWE-441 unintended proxy). The other three need an administrator account: CVE-2026-102256 (7.8) is an operating-system command injection that can give remote code execution, CVE-2026-102257 (7.2) is a Zip Slip path traversal in the Appliance Management Console (AMC) that can also lead to code execution, and CVE-2026-102258 (5.5) is stored cross-site scripting in AMC. SonicWall says it has no evidence any of the four are being exploited, lists no workaround, and says SSL-VPN on SonicWall firewalls and the SMA 100 series are not affected. Benoît Sevens of Anthropic reported the SSRF and command-injection bugs; Brian Mariani reported the Zip Slip through Trend Micro's Zero Day Initiative and the XSS through DigitalCanion SA. Important for anyone who patched last month: the builds that fixed the exploited September zero-days CVE-2026-83548 and CVE-2026-83549 (12.4.3-03526 and 12.5.0-02952) are the last affected builds in this advisory. Shadowserver tracks more than 400 internet-exposed SMA1000 appliances, and CISA has added 19 SonicWall flaws to its exploited list in four years, so expect attention. Primary: SonicWall PSIRT advisory; wires: BleepingComputer and Cyber Security News (7 Oct).

Product
SonicWall SMA1000 series (SMA 6210, SMA 7210, SMA 8200v; physical and virtual)
Versions
12.4.3-03526 and earlier; 12.5.0-02952 and earlier. Not affected: SMA 100 series, SSL-VPN on SonicWall firewalls.
CVSS
10.0 (CVE-2026-102255); 7.8 (CVE-2026-102256); 7.2 (CVE-2026-102257); 5.5 (CVE-2026-102258)
Exploited in Australia?
unknown
Patch to
Install platform-hotfix 12.4.3-03670 or later, or 12.5.0-03082 or later, from MySonicWall on every SMA1000 appliance. A device that took September's zero-day fix is still exposed, so check the installed build on each one. There is no workaround; until patched, limit who can reach WorkPlace and keep the management console off the internet.

Primary: SonicWall PSIRT — SNWLID-2026-0017, SMA1000 series multiple vulnerabilities (6 Oct 2026) · Vendor: BleepingComputer — SonicWall warns of max severity SSRF flaw in SMA1000 gateways (7 Oct 2026) · CVE: CVE-2026-102255, CVE-2026-102256, CVE-2026-102257, CVE-2026-102258, CVE-2026-83548, CVE-2026-83549 · Cyber Security News — SonicWall patches 4 SMA1000 flaws, including critical pre-auth SSRF rated CVSS 10 (7 Oct 2026)

vulnerabilities network