Threat reportVulnerabilityTL-2026-3022
SonicWall SMA1000 Four Flaws Patched Incl. Critical Pre-Auth SSRF CVE-2026-102255 (CVSS 10.0)
SonicWall SMA1000 Four Flaws Patched Incl. Critical Pre-Auth (TL-2026-3022), also tracked as SNWLID-2026-0017, is a critical-severity software vulnerability scored CVSS 10, first published 2026-10-07. It has no confirmed attribution, affects SonicWall SMA1000 (SMA 6210, SMA 7210, SMA 8200v), references 4 CVEs (CVE-2026-102255, CVE-2026-102256, CVE-2026-102257), maps to 6 MITRE ATT&CK techniques (T1059, T1059.004, T1059.007), and is covered by 9 detection rules and 12 indicators of compromise.
- CVSS
- 10/10Critical
- CVEs
- 4Referenced vulnerabilities
- Techniques
- 6MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 12Indicators of compromise
Key facts for TL-2026-3022
- Threat ID
- TL-2026-3022
- Also known as
- SNWLID-2026-0017, ZDI-CAN-28924
- Severity
- CRITICAL
- CVSS
- 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, finance, health, technology, critical-infrastructure
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 12
How SonicWall SMA1000 Four Flaws Patched Incl. Critical Pre-Auth works
SonicWall patched four vulnerabilities in SMA1000 secure-access appliances (SMA 6210, 7210, 8200v): a CVSS 10.0 pre-authentication SSRF in the WorkPlace interface caused by an unintended alternate access path that lets the device act as a forward proxy, a post-auth OS command injection (7.8), a Zip Slip in the Appliance Management Console leading to RCE (7.2), and a stored XSS. SonicWall reports no evidence of in-the-wild exploitation, but earlier SMA1000 flaws in the same product line were exploited.
On 2026-10-06/07 SonicWall published advisory SNWLID-2026-0017 covering four vulnerabilities in the SMA1000 series (models SMA 6210, 7210 and 8200v, physical and virtual). SSL-VPN services on SonicWall firewalls and the SMA 100 Series are not affected.
CVE-2026-102255 (CVSS 10.0, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H; CWE-918, CWE-441) is a pre-authentication SSRF in the SMA1000 Appliance WorkPlace interface. An 'unintended alternate access path' allows the device to act as a forward proxy, so an unauthenticated remote attacker can make the appliance issue requests and reach internal functionality without credentials. CVE-2026-102256 (CVSS 7.8, CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H; CWE-78) is a post-authentication OS command injection that lets an authenticated administrator execute arbitrary OS commands. CVE-2026-102257 (CVSS 7.2, CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H; CWE-22) is a Zip Slip in the Appliance Management Console (AMC): a specially crafted archive extracts files outside the intended destination directory, resulting in remote code execution. CVE-2026-102258 is a post-auth stored XSS in the AMC letting an authenticated administrator run arbitrary JavaScript; the vendor advisory rates it 5.5 while NVD lists CVSS 6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N; CWE-79).
Vulnerable builds are 12.4.3-03526 and earlier and 12.5.0-02952 and earlier; fixed builds are 12.4.3-03670 or later and 12.5.0-03082 or later, delivered via the MySonicWall portal. No workaround exists. The September 2026 builds (12.4.3-03526 / 12.5.0-02952), which fixed the previously exploited CVE-2026-83548 / CVE-2026-83549, do NOT address these flaws, so a fresh upgrade is required. SonicWall states there is no evidence of exploitation in the wild; no public PoC, IOCs, or threat-actor attribution are stated in the sources. Credits: Benoit Sevens (Anthropic) for the SSRF and command injection; Brian Mariani via Trend Micro ZDI (ZDI-CAN-28924) for the Zip Slip; DigitalCanion SA for the XSS.
Defender context: the SMA1000 line has been a repeated target. SonicWall disclosed an unauthenticated SSRF (CVE-2026-15409, CVSS 10.0) and an AMC command injection (CVE-2026-15410, CVSS 7.2) on 2026-07-14, both added to CISA KEV as exploited, and a September SSRF (CVE-2026-83548) plus command injection (CVE-2026-83549) also reported as exploited. An SSRF/forward-proxy primitive on an internet-facing remote-access appliance chained with admin-only command injection or Zip Slip is the same pattern, so rapid patching and review of appliance and authentication logs for anomalous requests is warranted.
MITRE ATT&CK techniques used in TL-2026-3022
Execution
T1059 Command and Scripting Interpreter; T1059.004 Command and Scripting Interpreter: Unix Shell; T1059.007 Command and Scripting Interpreter: JavaScript
Persistence
Command and Control
Initial Access
Affected products and versions in SonicWall SMA1000 Four Flaws Patched Incl. Critical Pre-Auth
- SonicWall — SMA1000 (SMA 6210, SMA 7210, SMA 8200v)
Vulnerable versions: 12.4.3-03526 and earlier; 12.5.0-02952 and earlier
Fixed in: 12.4.3-03670 and later; 12.5.0-03082 and later
Remediation for SonicWall SMA1000 Four Flaws Patched Incl. Critical Pre-Auth
Patches
- SMA1000 12.4.3-03670 or later
- SMA1000 12.5.0-03082 or later
Immediate actions
- Upgrade SMA 6210/7210/8200v to 12.4.3-03670 or later, or 12.5.0-03082 or later, via the MySonicWall portal
- Do not assume the September builds (12.4.3-03526 / 12.5.0-02952) are sufficient; they do not fix these CVEs
- Review appliance and authentication logs for anomalous requests, including requests the appliance originates to internal ranges
Workarounds
- None available per SonicWall
Longer-term hardening
- Restrict the AMC management interface to a dedicated management network
- Apply egress filtering on the appliance to limit reachable internal endpoints
- Monitor SonicWall PSIRT for further SMA1000 advisories given repeated 2026 exploitation of this product line
CVEs associated with SonicWall SMA1000 Four Flaws Patched Incl. Critical Pre-Auth
CVE-2026-102255, CVE-2026-102256, CVE-2026-102257, CVE-2026-102258
Weaknesses (CWE) in SonicWall SMA1000 Four Flaws Patched Incl. Critical Pre-Auth
Timeline of SonicWall SMA1000 Four Flaws Patched Incl. Critical Pre-Auth
- SonicWall disclosed SMA1000 SSRF CVE-2026-15409 (CVSS 10.0) and AMC command injection CVE-2026-15410 (CVSS 7.2) under advisory SNWLID-2026-0008; both confirmed exploited in the wild per Sophos and added to CISA KEV the same day
- SonicWall published SNWLID-2026-0016 fixing pre-auth SSRF CVE-2026-83548 (CVSS 10.0) and AMC command injection CVE-2026-83549 (CVSS 7.8), confirmed exploited in the wild, in builds 12.4.3-03526 and 12.5.0-02952; previously vulnerable builds were 12.4.3-03453 and 12.5.0-02835 and older
- CVE-2026-83548 added to CISA KEV at 18:00 UTC per CraftedSignal, with a recommended remediation action date of 2026-09-05
- SonicWall published advisory SNWLID-2026-0017 for four SMA1000 vulnerabilities; fixed builds 12.4.3-03670 and 12.5.0-03082
- Cyber Security News reported the patches; SonicWall states no evidence of in-the-wild exploitation and no workaround exists
- NVD published CVE-2026-102255, CVE-2026-102256, CVE-2026-102257 and CVE-2026-102258
Sources cited for SonicWall SMA1000 Four Flaws Patched Incl. Critical Pre-Auth
- SonicWall PSIRT SNWLID-2026-0017
- SonicWall Patches 4 SMA1000 Flaws, Including Critical Pre-Auth SSRF Rated CVSS 10
- NVD CVE-2026-102255
- NVD CVE-2026-102256
- NVD CVE-2026-102257
- NVD CVE-2026-102258
- Sophos: SonicWall SMA1000 vulnerabilities in active exploitation (CVE-2026-15409 / CVE-2026-15410)
- Ampcus Cyber: Actively exploited SonicWall SMA1000 flaws, pre-auth SSRF (CVE-2026-83548) and RCE
- CraftedSignal brief: SonicWall SMA1000 SSRF (SNWLID-2026-0016)
- SonicWall Product Notice: SMA 1000 affected by multiple vulnerabilities
Detection coverage for TL-2026-3022
As of 2026-10-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3022 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.