SONICWALL has released hotfixes for four vulnerabilities affecting its SMA1000 remote access appliances, including a maximum-severity pre-authentication SSRF flaw tracked as CVE-2026-102255. The flaw resides in the WorkPlace portal and could let an unauthenticated attacker direct the appliance to make internal requests and access internal functions, potentially enabling unauthorized operations. SonicWall states there is no evidence of active exploitation at this time, but officials urge applying the fixes promptly. The report notes the vulnerability does not impact SSL-VPN on SonicWall firewalls or the SMA 100 Series.
The affected SMA1000 models are 6210, 7210, and 8200v running versions 12.4.3-03526 (platform-hotfix) or older, and 12.5.0-02952 (platform-hotfix) or older. The hotfixes are available via the MySonicWall portal, with no workaround published.
In addition to CVE-2026-102255, three authenticated flaws are addressed: CVE-2026-102256 (OS command injection; CVSS 7.8) could allow an authenticated administrator to execute arbitrary commands; CVE-2026-102257 (Zip Slip; CVSS 7.2) could enable remote code execution via the Appliance Management Console; and CVE-2026-102258 (stored XSS; CVSS 5.5) could permit an authenticated administrator to store and run malicious JavaScript in the management console. Earlier in September, SonicWall patched two zero-days in SMA 1000 VPNs (CVE-2026-83548 and CVE-2026-83549) after confirming exploitation.