SonicWall has patched four vulnerabilities in its SMA 1000 series appliances, including CVE-2026-102255, a pre-authentication SSRF flaw that could let remote attackers trigger internal requests and unauthorized actions. The issues affect physical and virtual models 6210, 7210, and 8200v, and customers are advised to upgrade to firmware versions 12.4.3-03670 or higher, or 12.5.0-03082 or higher. #SonicWall #SMA1000 #CVE-2026-102255 #CVE-2026-102256 #CVE-2026-102257 #CVE-2026-102258
Keypoints
- SonicWall fixed four vulnerabilities in the SMA 1000 series appliances.
- CVE-2026-102255 is a pre-authentication SSRF flaw that can expose internal functionality.
- CVE-2026-102256 is a post-authentication OS command injection issue.
- CVE-2026-102257 and CVE-2026-102258 affect the Appliance Management Console and require admin access.
- Customers should upgrade SMA 1000 appliances to firmware 12.4.3-03670 or 12.5.0-03082 and later.