Breaking
SecurityConfirmed

New SonicWall Flaw Hits VPN Gateways

SonicWall issued hotfixes for a maximum-severity SSRF bug in SMA1000 appliances, urging customers to upgrade before attackers take note.

··2 hours ago·6 min read
a close up of a network with wires connected to it
Photo by Albert Stoynov on Unsplash

SonicWall has shipped hotfixes for a maximum-severity server-side request forgery flaw affecting its SMA1000 series appliances, and the company is asking customers to move to the fixed release. The bug, tracked as CVE-2026-102255, lives in the Appliance WorkPlace interface of the SMA1000 6210, 7210, and 8200v models. It does not touch the SMA 100 Series product line or SSL-VPN running on SonicWall firewalls, which narrows the pool of systems at risk but does not make the issue less urgent for the organizations running the affected hardware.

An alternate path into the appliance

The vulnerability grew out of what SonicWall describes as an unintended alternate access-path weakness. That kind of defect typically appears when a component exposes more than the developers intended, leaving a route that was never meant to be reachable. Here, the route is reachable by a remote attacker who holds no privileges on the device.

Because the attack requires no credentials and, per the company, is low in complexity, the barrier to trying it is minimal. An attacker does not need to be authenticated, does not need to be on the internal network, and does not need to chain multiple bugs to get a first foothold.

What the SSRF actually does

SonicWall's own description of the mechanism is specific. The company explained the consequences of the alternate path in its advisory.

"By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations."

— SonicWall, in its advisory on the SMA1000 hotfix release

In plain terms, the appliance can be made to act as a proxy for the attacker. Requests the attacker could not send directly get issued by the gateway itself, which sits inside the network and is trusted by the systems around it. That is the core risk of an SSRF in a device of this class: it turns the appliance's own position into an attacker's tool.

The models in scope

The flaw is confined to specific hardware and virtual form factors. SonicWall lists the SMA1000 6210, 7210, and 8200v as affected. The company separately confirmed that the SMA 100 Series product line is not impacted, and neither is SSL-VPN running on SonicWall firewalls.

That scoping matters for defenders trying to work out whether they need to act today. Organizations running the named SMA1000 models should treat the hotfix as required. Teams running the SMA 100 Series or SSL-VPN on a SonicWall firewall can rule this particular CVE out.

No evidence of exploitation yet

SonicWall has not flagged CVE-2026-102255 as actively exploited. The company was explicit about that in its advisory.

"SonicWall strongly advises users of the SMA1000 series appliances to upgrade to the mentioned fixed release version to address these vulnerabilities."

"There is currently no evidence any of the vulnerabilities addressed in this release are being exploited in the wild."

— SonicWall, in its advisory on the SMA1000 hotfix release

That absence of evidence is the reason the vendor is pushing customers to patch now rather than after a detection. The hotfixes were released on Tuesday and are aimed at blocking potential attacks against both virtual and physical appliances.

Hundreds of gateways sit exposed

Shadowserver, an internet security threat watchdog, currently tracks over 400 Internet-exposed SMA1000 appliances. Some of those may already have been patched, so the figure is an upper bound on the population that is reachable from the public internet.

  • Over 400 Internet-exposed SMA1000 appliances tracked by Shadowserver
  • CVE-2026-102255 — the SSRF flaw in the Appliance WorkPlace interface
  • 19 SonicWall vulnerabilities added to CISA's actively exploited list over the last four years
  • 13 of those 19 have also been abused in ransomware attacks

Exposure alone does not mean compromise, but it defines the population an attacker could scan and probe without ever touching a victim's perimeter from the inside.

Why attackers watch this product line

SMA1000 flaws draw attention because of what the appliances do. These are enterprise-grade secure remote access gateways, used by government agencies, Managed Service Providers, and many large corporations to hand VPN access to internal apps and corporate networks. A gateway is, by design, a doorway between the outside world and the interior.

Since the start of the year, threat actors have exploited several SMA1000 security vulnerabilities in zero-day attacks. In July, two SMA1000 zero-days — CVE-2026-15409 and CVE-2026-15410 — were exploited for weeks to install custom Sou5, OrangeTail, and RootRun malware on vulnerable VPN appliances. The U.S. Cybersecurity and Infrastructure Security Agency linked those attacks to ransomware gangs.

Last month, SonicWall warned customers that attackers were chaining two new zero-days, CVE-2026-83548 and CVE-2026-83549, to execute remote code on vulnerable SMA1000 gateways.

The longer exploitation record

The pattern is not confined to this year. CISA has added 19 SonicWall vulnerabilities to its list of actively exploited flaws over the last four years, and 13 of those have also been abused in ransomware attacks. That tally is a matter of public record and covers the vendor's products broadly rather than the SMA1000 line alone.

For defenders, the relevant point is that this product family has a track record of being attacked in the wild — sometimes as a zero-day, before a patch is available. CVE-2026-102255 is not in that category yet, but the fix exists now, which puts the decision entirely in customers' hands.

What customers should do

The action SonicWall wants is straightforward: upgrade the SMA1000 series appliances to the fixed release. The company's advisory points users to the mentioned fixed release version as the way to address the vulnerabilities in this set.

Because the hotfixes cover both virtual and physical form factors, teams running the 8200v alongside the 6210 and 7210 have a single upgrade path to follow. Those on the SMA 100 Series or SSL-VPN on SonicWall firewalls have no action to take for this specific CVE.

The advisory is the authoritative source for which release to move to and any prerequisites attached to the upgrade. Administrators who manage these gateways on behalf of others — MSSPs in particular — should work through their fleet to confirm which instances fall on the affected models.

Why this matters beyond one patch cycle

The immediate stake for any organization running an affected SMA1000 is the same one that has played out repeatedly with this product line: a remote-access gateway is a high-value position, and CVE-2026-102255 does not require the attacker to authenticate before making the appliance act on their behalf. Given that CISA has already linked 13 SonicWall flaws to ransomware attacks over four years, the downside of leaving an affected appliance on an older release is not hypothetical for the organizations that depend on these devices for VPN access to internal applications.

For readers who do not run SonicWall hardware, the story still has a use. It is a reminder that the remote-access layer — the box that lets employees in from outside — is where a lot of enterprise risk concentrates, and that vendors in this space are now disclosing and patching flaws on a cadence that leaves little room for a relaxed upgrade schedule. The absence of exploitation evidence in this case could mean the bug has not been found by attackers yet, or simply that no one has reported it. Either way, the hotfix is available, and the exposed population Shadowserver can see from the outside is the population an attacker can see too.

#sonicwall#ssrf#vpn#cve-2026-102255#sma1000#vulnerability

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories