SonicWall Critical SSRF Vulnerability Affects SMA1000 Gateways
SonicWall has issued patches to address a critical server-side request forgery vulnerability affecting SMA1000 series appliances, with recent zero-day exploits highlighting the urgency of timely patch management.
Critical Vulnerability in SonicWall SMA1000 Series
Vulnerability Details (CVE-2026-102255)
The flaw, designated CVE-2026-102255, resides within the Appliance WorkPlace interface of specific models including 6210, 7210, and 8200v variants.
Affected Models and Scope
This issue does not affect the SMA 100 Series or SSL-VPN implementations on SonicWall firewalls.
Exploitation Risks and Recommendations
The vulnerability arises from an unintended alternate access path that enables unauthenticated remote attackers to manipulate the appliance into initiating requests to internal systems. Exploitation could allow adversaries to access restricted functionalities and perform unauthorized actions. Although no active exploitation has been confirmed, the vendor recommends immediate deployment of the recently released hotfixes to prevent potential threats. The advisory emphasizes that there is no evidence of these vulnerabilities being leveraged in real-world attacks.
Shadowserver’s Findings
Shadowserver reports over 400 internet-facing SMA1000 devices, though some may have already been remediated.
Importance of the Devices
The vulnerability’s potential to compromise enterprise-grade secure remote access gateways has drawn attention due to their use by government entities, managed service providers, and large organizations for VPN connectivity.
Recent Threat Activity and CISA Advisory
Zero-Day Exploits in July
Recent threat activity has shown adversaries exploiting multiple SMA1000 vulnerabilities in zero-day attacks. In July, two unpatched flaws (CVE-2026-15409 and CVE-2026-15410) were used to deploy custom malware families such as Sou5, OrangeTail, and RootRun on vulnerable appliances, with U.S. CISA attributing these campaigns to ransomware operators.
Recent Zero-Days in August
Earlier this month, another pair of zero-days (CVE-2026-83548 and CVE-2026-83549) were linked to remote code execution attempts on SMA1000 gateways.
CISA’s Documentation of Exploited Vulnerabilities
CISA has documented 19 SonicWall vulnerabilities as actively exploited over the past four years, with 13 of these also associated with ransomware operations. The advisory underscores the importance of timely patch management for critical infrastructure components.
