SonicWall warns of max severity SSRF flaw in SMA1000 gateways
Source reporting says attackers are already exploiting this, so exposed SonicWall firewalls & SMA systems are at immediate risk.
Treat this as an emergency.
No official fix confirmed yet
Until a fix ships, follow the vendor's mitigations, limit exposure of affected systems, and watch this record for a patch.
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations.
Source: NIST National Vulnerability Database. Official vulnerability data, reproduced as published.
Developments from the last 30 days, newest first.
CVE-2026-102255 scored CVSS 10.0
Basis: NIST National Vulnerability Database
Source reporting says attackers are already exploiting this, so exposed SonicWall firewalls & SMA systems are at immediate risk.
Treat this as an emergency.