CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

SonicWall SMA1000: pre-authentication SSRF in the Work Place interface (CVSS 3.0 10.0), affects the September hotfix builds

cve · CVE-2026-102255

Coverage
1
first 2026-10-08 → last 2026-10-08
Latest activity
2026-10-08
SonicWall patches a third pre-auth CVSS 10.0 SMA1000 SSRF; the September hotfix builds are affected
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, technology · regions: europe
Sources cited
6
6 hosts

Action items (1)

Do-now tasks recorded on the entries about CVE-2026-102255, newest first. Check the date before acting on an older one.

  • Install SonicWall's platform hotfix 12.4.3-03670 or 12.5.0-03082 (or higher) on every SMA1000 6210, 7210 and 8200v, including appliances already on the 12.4.3-03526 or 12.5.0-02952 hotfix from September; the appliance restarts when the installation finishes and no workaround is listed.
    2026-10-08CVE-2026-102255 +3

Defender insights

What each entry about CVE-2026-102255 tells a defender to do, newest first.

2026-10-08HIGHSonicWall patches a third pre-auth CVSS 10.0 SMA1000 SSRF; the September hotfix builds are affected

Exposure · detection

Story timeline

  1. 2026-10-08CVE-2026-102255, SonicWall SMA1000: a third unauthenticated CVSS 10.0 Work Place SSRF this year, and it affects the hotfix builds that closed the September zero-days (no exploitation reported)
    trending-vulnerabilitiesSonicWall patches a third pre-auth CVSS 10.0 SMA1000 SSRF; the September hotfix builds are affected
ATT&CK techniques (2 across 2 tactics)

2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessExploit Public-Facing Application
  • ExecutionCommand and Scripting Interpreter

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-10-08/cve-2026-102255-sonicwall-sma1000-workplace-ssrf · ATT&CK page ↗

Execution TA0002

T1059Command and Scripting Interpreter×1

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.

Evidence: 2026-10-08/cve-2026-102255-sonicwall-sma1000-workplace-ssrf · ATT&CK page ↗

Entries about SonicWall SMA1000: pre-authentication SSRF in the Work Place interface (CVSS 3.0 10.0), affects the September hotfix builds (1)

2026-10-08 · view entry permalink →

CVE-2026-102255, SonicWall SMA1000: a third unauthenticated CVSS 10.0 Work Place SSRF this year, and it affects the hotfix builds that closed the September zero-days (no exploitation reported)

SonicWall's advisory SNWLID-2026-0017 of 2026-10-06 fixes four flaws in the SMA1000 secure remote-access appliances (models 6210, 7210 and 8200v). CVE-2026-102255 (CVSS 3.0 10.0) is a pre-authentication server-side request forgery in the Work Place interface, attributed to an unintended alternate access path, through which a remote unauthenticated attacker can direct the appliance to issue requests on their behalf, reach internal functionality and perform unauthorized operations (SonicWall PSIRT, 2026-10-06). The other three flaws need a login: an OS command injection that lets an administrator execute commands (CVE-2026-102256, 7.8), a Zip Slip in the Appliance Management Console that leads to code execution (CVE-2026-102257, 7.2) and a stored cross-site scripting flaw in that console (CVE-2026-102258, 5.5) (SonicWall PSIRT, 2026-10-06). SonicWall says there is currently no evidence that any of them is exploited (SonicWall PSIRT, 2026-10-06).

The pre-authentication flaw is not routine because of what came before it. The Hacker News counts it as the third time this year that SonicWall has fixed a 10.0-rated Work Place SSRF that needs no login; in July and September SonicWall said it had investigated attacks on the earlier pairs ("multiple cases" and "a case"), each pair combining an SSRF that needs no login with a second flaw that lets a logged-in administrator run commands (The Hacker News, 2026-10-07). CERT-FR notes that such pairs have been actively exploited several times this year on this product (CERT-FR, 2026-10-07). The affected builds include 12.4.3-03526 and 12.5.0-02952, the hotfixes SonicWall named on 1 September for the two exploited flaws, so an appliance patched against that chain is still affected (The Hacker News, 2026-10-07). Fixed builds are 12.4.3-03670 and 12.5.0-03082 and higher (The Hacker News, 2026-10-07; CERT-FR, 2026-10-07), whereas the Canadian Cyber Centre's bulletin lists the same two builds as affected "and prior" (Canadian Cyber Centre, 2026-10-07). Shadowserver tracks over 400 internet-exposed SMA1000 appliances, some of which may already be patched, and BleepingComputer says government agencies and managed service providers use the product to give VPN access to internal applications (BleepingComputer, 2026-10-07). NCSC Switzerland published an advisory on 2026-10-07 and lists the exploitation status as unknown (NCSC Switzerland, 2026-10-07).

There is currently no evidence any of the vulnerabilities addressed in this release are being exploited in the wild.

SonicWall PSIRT (advisory SNWLID-2026-0017) 2026-10-06

It is the third time this year that SonicWall has fixed a 10.0-rated SSRF flaw in WorkPlace that needs no login.

12.4.3-03670 and higher versions are fixed.

12.5.0-03082 and higher versions are fixed.

The Hacker News 2026-10-07

Builds on: SonicWall confirms active exploitation of an unauthenticated SMA1000 SSRF chained to code… · The second SonicWall SMA1000 zero-day chain in seven weeks, and this time the vendor's own…

vulnerability08 Oct 04:50Zmulti-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Vulns1

Source distribution

  • bleepingcomputer.com1 (17%)
  • cert.ssi.gouv.fr1 (17%)
  • cyber.gc.ca1 (17%)
  • psirt.global.sonicwall.com1 (17%)
  • security-hub.ncsc.admin.ch1 (17%)
  • thehackernews.com1 (17%)