SonicWall PSIRT
sonicwall-psirt · A · candidate
https://psirt.global.sonicwall.com/vuln-list
Added 2026-10-08: S1 candidate; the vendor PSIRT behind three SMA1000 exploited-zero-day advisories in 2026 and SNWLID-2026-0017, the primary of a published entry. The vuln-list page reads through the reader with advisory id, CVEs and release dates; the vuln-detail pages are an SPA whose reader body omits the fixed-version table, so fixed builds came from press and CERT-FR. Recipe is reader-only (`jina`).
Cited in 3 entries
Citation cadence
Citation days per ISO week (13 weeks of coverage span, total 3).
- CVE-2026-102255, SonicWall SMA1000: a third unauthenticated CVSS 10.0 Work Place SSRF this year, and it affects the hotfix builds that closed the September zero-days (no exploitation reported)2026-10-08
- CVE-2026-83548 / CVE-2026-83549, SonicWall SMA1000: a pre-auth SSRF through an unintended alternate Work Place access path chains into post-auth command injection in the Management Console, both under active exploitation2026-09-03
- CVE-2026-15409, SonicWall SMA1000: unauthenticated SSRF (CVSS 10.0) chained to post-auth code injection, actively exploited2026-07-14