SonicWall SMA1000: pre-authentication SSRF in the Work Place interface (CVSS 3.0 10.0), affects the September hotfix builds
cve · CVE-2026-102255
Action items (1)
Do-now tasks recorded on the entries about CVE-2026-102255, newest first. Check the date before acting on an older one.
- Install SonicWall's platform hotfix 12.4.3-03670 or 12.5.0-03082 (or higher) on every SMA1000 6210, 7210 and 8200v, including appliances already on the 12.4.3-03526 or 12.5.0-02952 hotfix from September; the appliance restarts when the installation finishes and no workaround is listed.2026-10-08CVE-2026-102255 +3
Defender insights
What each entry about CVE-2026-102255 tells a defender to do, newest first.
Story timeline
ATT&CK techniques (2 across 2 tactics)
2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
- ExecutionCommand and Scripting Interpreter
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-10-08/cve-2026-102255-sonicwall-sma1000-workplace-ssrf · ATT&CK page ↗
Execution TA0002
T1059Command and Scripting Interpreter×1
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.
Evidence: 2026-10-08/cve-2026-102255-sonicwall-sma1000-workplace-ssrf · ATT&CK page ↗
Entries about SonicWall SMA1000: pre-authentication SSRF in the Work Place interface (CVSS 3.0 10.0), affects the September hotfix builds (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- SonicWall SMA 1000×1
- SonicWall SMA1000: post-authentication OS command injection (CVSS 3.0 7.8)×1
- SonicWall SMA1000: post-authentication stored XSS in the Appliance Management Console (CVSS 3.0 5.5)×1
- SonicWall SMA1000: post-authentication Zip Slip in the Appliance Management Console (CVSS 3.0 7.2)×1
Where this entity is cited
Source distribution
- bleepingcomputer.com1 (17%)
- cert.ssi.gouv.fr1 (17%)
- cyber.gc.ca1 (17%)
- psirt.global.sonicwall.com1 (17%)
- security-hub.ncsc.admin.ch1 (17%)
- thehackernews.com1 (17%)
External references
All cited sources (6)
- psirt.global.sonicwall.comprimarySonicWall PSIRT (advisory SNWLID-2026-0017)https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0017
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/sonicwall-warns-of-max-severity-ssrf-flaw-in-sma1000-gateways/
- cert.ssi.gouv.frCERT-FRhttps://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1275/
- cyber.gc.caCanadian Centre for Cyber Security (AV26-1017)https://cyber.gc.ca/en/alerts-advisories/sonicwall-security-advisory-av26-1017
- security-hub.ncsc.admin.chNCSC Switzerland (Security Hub advisory)https://security-hub.ncsc.admin.ch/#/posts/13034
- thehackernews.comThe Hacker Newshttps://thehackernews.com/2026/10/sonicwall-patches-cvss-100-pre.html