SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances
SonicWall has issued hotfixes for four vulnerabilities in SMA1000 appliances, including a critical unauthenticated SSRF flaw in WorkPlace that could let attackers reach internal functions. The flaws affect specific SMA1000 versions, require different access levels, and there is no evidence yet of active exploitation. #SonicWall #SMA1000 #CVE-2026-102255 #CVE-2026-102256 #CVE-2026-102257 #CVE-2026-102258

Keypoints

  • SonicWall released hotfixes for four flaws in SMA1000 appliances.
  • CVE-2026-102255 is a critical SSRF bug in WorkPlace that needs no login.
  • The other three flaws require login, including one that could lead to remote code execution.
  • Affected models include SMA1000 6210, 7210, and 8200v on specific platform-hotfix versions.
  • SonicWall says there is no evidence the flaws are being exploited, and no workaround is available.

Read More: https://thehackernews.com/2026/10/sonicwall-patches-cvss-100-pre.html