
A new critical vulnerability in SonicWall SMA1000 appliances deserves immediate attention from organizations using the platform as an internet-facing remote-access gateway.
Tracked as CVE-2026-102255, the vulnerability is a pre-authentication Server-Side Request Forgery (SSRF) flaw in the SMA1000 Appliance WorkPlace interface. It carries the maximum CVSS v3.1 score of 10.0.
What is the vulnerability?
The flaw exists because of an unintended alternate access path in the WorkPlace interface.
An unauthenticated remote attacker could abuse this path to make the SMA1000 appliance issue requests on the attacker’s behalf. This could allow the attacker to reach internal functionality and perform unauthorized operations.
The important point is that authentication is not required.
The CVSS vector is:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
In practical terms, the vulnerability is remotely exploitable, requires low attack complexity, needs no credentials or user interaction, and has potentially high impact across confidentiality, integrity and availability.
The weakness is classified under CWE-918 (SSRF) and CWE-441 (Unintended Proxy or Intermediary).
Affected SonicWall products
The vulnerability affects the SMA1000 series, including:
- SMA 6210
- SMA 7210
- SMA 8200v
Affected versions are:
- 12.4.3-03526 and earlier
- 12.5.0-02952 and earlier
The issue does not affect SonicWall firewall-based SSL-VPN or the SMA 100 Series product line.
Patch available
SonicWall has released fixes for the vulnerability.
Organizations should upgrade to:
- 12.4.3-03670 or later
- 12.5.0-03082 or later
The fixes are available through the MySonicWall portal. SonicWall has not provided a workaround, making the vendor hotfix the primary remediation path.
Is CVE-2026-102255 being exploited?
At the time of disclosure, SonicWall reported no evidence that CVE-2026-102255 or the other vulnerabilities covered by the advisory were being exploited in the wild. It is also not currently listed in the CISA KEV catalog.
That should not be interpreted as a reason to delay patching.
The SMA1000 WorkPlace interface has already been targeted by attackers through similar pre-authentication vulnerabilities in 2026. Earlier flaws, including CVE-2026-15409 and CVE-2026-83548, were exploited as zero-days.
This history makes the latest vulnerability particularly important for internet-facing deployments.
What organizations should do now
Organizations running SMA1000 should:
- Identify all SMA1000 appliances exposed to the internet.
- Check the exact platform-hotfix version.
- Apply the SonicWall hotfix immediately if the appliance is running an affected release.
- Review security and access logs for unusual requests involving the WorkPlace interface.
- Investigate unexpected activity originating from the appliance toward internal services.
- Treat any previously exposed vulnerable appliance as a higher-priority asset for compromise assessment.
Patching should be prioritized even though exploitation has not been confirmed.
The bigger concern
CVE-2026-102255 is significant not simply because it has a CVSS score of 10.0, but because it sits at the intersection of three high-risk characteristics:
Internet-facing appliance + pre-authentication access + SSRF into internal functionality.
That combination can turn a perimeter security appliance into an unintended bridge toward resources that were never meant to be directly accessible by an external attacker.
For organizations running SMA1000, this is therefore a patch-now vulnerability rather than a wait-and-watch issue.


