← Blog
SonicWall SMA1000SSRFEdge ApplianceVPN Security

SonicWall SMA 1000 CVE-2026-102255: Max-Severity Pre-Auth SSRF

SonicWall patched CVE-2026-102255, a CVSS 10 pre-auth SSRF in SMA 1000 Work Place. No exploitation yet — but the same appliance was rooted in July.

Zero Hunt Research··6 min read

Published by Zero Hunt, an autonomous AI red team on an on-premise appliance running private AI: automated penetration testing for networks and infrastructure, black-box or gray-box, with a human approving every step that matters.

SonicWall released hotfixes on October 7, 2026 for four vulnerabilities in its SMA 1000 secure-access appliances, and one of them is a maximum-severity, pre-authentication server-side request forgery: CVE-2026-102255, scored CVSS 10.0. An unauthenticated attacker on the internet can make the appliance issue requests on their behalf and reach internal functionality that trusts it. SonicWall says there is no evidence of exploitation yet. That word — yet — is the whole point of this post, because the same SMA 1000 Work Place interface carried a CVSS 10.0 SSRF three months ago that went from disclosure to actively-exploited-to-root in a matter of hours.

Developing story — first published 13:55 CEST (11:55 UTC), 2026-10-07. Updated as SonicWall and CISA publish more.

At a glance

CVE CVE-2026-102255 (NVD record not yet published as of 2026-10-07)
Product / affected versions SMA 1000 series 6210 · 7210 · 8200v (physical and virtual); SMA 100 series and firewall SSL-VPN not affected
Fixed in 12.4.3-03670 and higher; 12.5.0-03082 and higher (hotfixes, 2026-10-07)
CVSS 10.0 · Critical (SonicWall; NVD not yet scored)
Exploited in the wild No evidence as of 2026-10-07 (SonicWall advisory statement)
CISA KEV Not listed (catalog version 2026.10.04)
Public PoC None public as of 2026-10-07 per the reporting sources
Official advisory SonicWall SNWLID-2026-0017

What SonicWall actually fixed

The headline bug, CVE-2026-102255, is a pre-authentication SSRF in the SMA 1000 Work Place interface — the portal that terminates remote-access sessions and therefore faces the internet by design. SonicWall describes it as an "unintended alternate access path" that lets a remote, unauthenticated attacker "direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations," per the vendor statement quoted by Help Net Security. The SSRF carries the perfect 10.0 because it needs no credentials, no user interaction, and the appliance's position on the trust boundary means "internal functionality" is not a sandbox — it is the management plane and the services the gateway already has a line to.

The other three, same advisory, all require an authenticated administrator and so rate lower:

  • CVE-2026-102256 — post-authentication OS command injection in the management console (CVSS 7.8).
  • CVE-2026-102257 — a Zip Slip path traversal that reaches remote code execution via a crafted archive (CVSS 7.2).
  • CVE-2026-102258 — stored cross-site scripting in the Appliance Management Console (CVSS 5.5).

The lesson of this appliance's July incident is that "requires admin" is not the brake it looks like. In July, SonicWall patched CVE-2026-15409 and CVE-2026-15410 — a CVSS 10.0 Work Place SSRF chained to an "admin-only" code injection — and both were already being exploited in live incidents. The SSRF put the attacker inside the trust boundary, which is exactly what makes a post-auth bug reachable. We wrote that chain up at the time in our SMA1000 SSRF-to-root analysis. CVE-2026-102255 is the same primitive on the same interface, caught before weaponization this time.

Who is exposed, and how to check

Shadowserver tracks more than 400 internet-exposed SMA 1000 appliances, and BleepingComputer notes CISA has catalogued 19 SonicWall vulnerabilities as exploited over time, 13 of them tied to ransomware. If you run one of the affected models, treat this as an edge-of-network emergency even without exploitation reports — the disclosure-to-exploitation window on this product has historically been short.

Check your running build from the appliance console or Central Management Server:

  • SMA 1000 standalone: System → Status, read the firmware string (e.g. 12.4.3-03xxx or 12.5.0-02xxx).
  • Anything on the 12.4.3 branch below -03670, or the 12.5.0 branch below -03082, is vulnerable.

Remediation

  1. Am I affected? Confirm the model is 6210, 7210, or 8200v and read the firmware build. SMA 100 series and SSL-VPN on SonicWall firewalls are not in scope for this advisory — do not patch the wrong fleet and declare victory.
  2. Patch — exact fixed versions. Apply the hotfix: 12.4.3-03670 and higher on the 12.4.3 branch, 12.5.0-03082 and higher on the 12.5.0 branch. There is no documented workaround; the upgrade is the fix.
  3. Can't patch this hour? Shrink the SSRF's reach. An SSRF is only as dangerous as what the appliance can talk to. Put the SMA 1000 in a segment whose egress is tightly allow-listed — it needs to reach your authentication back-ends and the services it proxies, and nothing else. Deny its outbound access to cloud metadata endpoints (169.254.169.254), to the management network, and to internal admin interfaces. This does not fix the bug; it limits what a forced request can hit (MITRE ATT&CK T1190, initial access via a public-facing application).
  4. Hunt for abuse of the window. There are no vendor-published IOCs for CVE-2026-102255 because there is no observed exploitation — so hunt on behavior, not signatures. The tell of an abused SSRF is the appliance originating connections it never normally makes: outbound requests from the SMA 1000's own IP to internal hosts, to localhost-equivalent loopback services, or to metadata endpoints. Pull the appliance's egress flow logs and your netflow for the gateway host and look for first-seen internal destinations in the days around disclosure. Map this to T1090 (proxy/relayed traffic): the appliance becomes the relay.
  5. Eradicate and verify. If you find the appliance made requests it should never originate, treat it as compromised: snapshot for forensics, rebuild from a known-good image rather than patching in place, and rotate every secret the gateway holds — admin credentials, API tokens, and the authentication-backend service accounts it can reach. Confirm clean after the rebuild, not before.

What is not known yet

  • The CVSS vector and CWE — SonicWall published the 10.0 score; the full vector string and NVD's independent analysis were not available at publication.
  • Whether a public PoC will appear. None exists as of this writing. Given the July precedent on the identical interface, assume reverse-engineering of the patch is already under way.
  • Any exploitation. SonicWall states none; that is a snapshot, not a guarantee, and it will change the moment a working PoC lands against 400+ exposed boxes.

Where Zero Hunt fits

A firmware string tells you whether you are patched. It does not tell you whether the pre-auth SSRF was reachable on your deployment during the window before you patched, or whether anyone walked through it. With no public PoC, the only honest way to answer that is to prove it on your own appliance before an attacker does.

That is what Zero Hunt's autonomous AI red team does against an edge appliance like the SMA 1000: a 10-agent swarm runs black-box against the real device on the perimeter, and when exact product and version identification points to a reachable weakness, a sealed coding agent writes a per-target proof-of-concept — a local model on the on-prem appliance, no public exploit to wait for, no code leaving the box — and iterates until the SSRF either demonstrably reaches internal functionality or demonstrably does not. Every step runs in an ephemeral container with a human in the loop gating anything that touches the live gateway, and every finding is signed at write time. A change-triggered campaign re-runs the moment a new appliance appears on the perimeter — which is exactly the cadence the July attackers used against this same product.

The second blind spot is detection during the quiet window. A pre-auth SSRF leaves no malware and trips no signature; its only tell is the appliance suddenly acting as a relay into the network it is supposed to guard. Zero Hunt's AI Traffic Analysis — a deep-learning model with four inference heads, trained on billions of PCAP sequences and running on the appliance GPU at 2.7+ Gbit/s — profiles what normal egress from your gateway looks like and flags the appliance originating internal requests it has never made, while it is happening, not in the next morning's SIEM digest.

If you want the regulatory framing for perimeter-appliance testing duties, our guide to automated penetration testing covers how continuous black-box validation maps to the testing obligations most frameworks now carry.

Every vulnerability CISA lists as exploited, with federal due dates: CISA KEV tracker →

Is this exploitable in your environment?

Zero Hunt answers that on your own network: an autonomous AI red team on an on-premise appliance, running on private AI, black-box or gray-box, with a human approving every step that matters. Proof of what is exploitable, the fix, and signed evidence — no data leaves your perimeter.