SonicWall has released hotfixes for a maximum-severity server-side request forgery (SSRF) vulnerability in its SMA1000 series appliances that could let unauthenticated remote attackers reach internal functionality and perform unauthorized operations. Tracked as CVE-2026-102255, the flaw affects the Appliance WorkPlace interface of SMA1000 6210, 7210 and 8200v models, and does not impact the SMA 100 Series or SSL-VPN on SonicWall firewalls. The company said there is currently no evidence the vulnerability is being exploited in the wild.
SonicWall described the issue as an unintended alternate access-path weakness that remote attackers without privileges can exploit in low-complexity attacks.
"By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations," the company said.
While it has not flagged the flaw as actively exploited, SonicWall urged customers to deploy hotfixes released on Tuesday to block potential attacks on their virtual or physical appliances.
"SonicWall strongly advises users of the SMA1000 series appliances to upgrade to the mentioned fixed release version to address these vulnerabilities," the company added. "There is currently no evidence any of the vulnerabilities addressed in this release are being exploited in the wild."
Internet security watchdog Shadowserver currently tracks over 400 internet-exposed SMA1000 appliances, although some may already be patched.
Although CVE-2026-102255 is not exploited in the wild, attackers often target SMA1000 flaws because they affect enterprise-grade secure remote access gateways used by government agencies, managed service providers and large corporations to provide VPN access to internal applications and corporate networks.
Since the start of the year, threat actors have exploited several SMA1000 vulnerabilities in zero-day attacks. In July, two SMA1000 zero-days (CVE-2026-15409 and CVE-2026-15410) were exploited for weeks to install custom Sou5, OrangeTail and RootTail malware on vulnerable VPN appliances, in attacks the U.S. Cybersecurity and Infrastructure Security Agency (CISA) linked to ransomware gangs. Last month, SonicWall warned that attackers were chaining two new zero-days (CVE-2026-83548 and CVE-2026-83549) to execute remote code on vulnerable SMA1000 gateways.
Analysis
Why This Matters
- SMA1000 appliances sit at the network perimeter as secure remote access gateways, so an unauthenticated SSRF could give attackers a foothold inside government and corporate networks.
- This is the latest in a string of SMA1000 disclosures this year, following multiple zero-days, signalling that these gateways have become a favoured target.
- With hundreds of appliances still exposed to the internet, the window between disclosure and mass exploitation is the key risk.
Background
The SMA1000 series is SonicWall's line of enterprise-grade secure access gateways, used by government agencies, managed service providers and large corporations to provide VPN access to internal applications and corporate networks. Because they sit at the edge of these networks, they have become an attractive target.
This advisory lands in a difficult year for the platform. In July, two SMA1000 zero-days (CVE-2026-15409 and CVE-2026-15410) were exploited for weeks to install custom Sou5, OrangeTail and RootTail malware, with CISA linking the activity to ransomware gangs. Last month, SonicWall warned that attackers were chaining two further zero-days (CVE-2026-83548 and CVE-2026-83549) to achieve remote code execution on vulnerable appliances.
Key Perspectives
SonicWall: The vendor says there is no evidence of active exploitation, but strongly advises customers to deploy the hotfixes released on Tuesday and upgrade to the fixed release version.
Security researchers and watchdogs: Shadowserver's tracking of hundreds of internet-exposed SMA1000 appliances highlights the large attack surface. Researchers note attackers frequently target these gateways precisely because they front enterprise and government networks, making them high-value targets.
Critics and skeptics: Given the platform's track record this year, with several zero-days exploited before patches were widely deployed, the reassurance that this flaw is not yet exploited may offer limited comfort. The repeated disclosures raise questions about how quickly organisations are patching these devices, and whether the SMA1000 line carries a broader security burden.
What to Watch
- Whether exploitation of CVE-2026-102255 is detected in the coming weeks, which would follow the pattern of earlier SMA1000 flaws.
- The number of internet-exposed SMA1000 appliances tracked by Shadowserver; a slow decline would indicate slow patch adoption.
- Whether SonicWall issues follow-up advisories, given that attackers have repeatedly chained multiple SMA1000 flaws this year.