Threat reportVulnerabilityTL-2026-3022

SonicWall SMA1000 Four Flaws Patched Incl. Critical Pre-Auth SSRF CVE-2026-102255 (CVSS 10.0)

criticalPATCHED

SonicWall SMA1000 Four Flaws Patched Incl. Critical Pre-Auth (TL-2026-3022), also tracked as SNWLID-2026-0017, is a critical-severity software vulnerability scored CVSS 10, first published 2026-10-07. It has no confirmed attribution, affects SonicWall SMA1000 (SMA 6210, SMA 7210, SMA 8200v), references 4 CVEs (CVE-2026-102255, CVE-2026-102256, CVE-2026-102257), maps to 6 MITRE ATT&CK techniques (T1059, T1059.004, T1059.007), and is covered by 9 detection rules and 12 indicators of compromise.

CVSS
10/10Critical
CVEs
4Referenced vulnerabilities
Techniques
6MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
12Indicators of compromise

Key facts for TL-2026-3022

Threat ID
TL-2026-3022
Also known as
SNWLID-2026-0017, ZDI-CAN-28924
Severity
CRITICAL
CVSS
10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, finance, health, technology, critical-infrastructure
Target regions
Global
Detection rules
9
Indicators of compromise
12

How SonicWall SMA1000 Four Flaws Patched Incl. Critical Pre-Auth works

SonicWall patched four vulnerabilities in SMA1000 secure-access appliances (SMA 6210, 7210, 8200v): a CVSS 10.0 pre-authentication SSRF in the WorkPlace interface caused by an unintended alternate access path that lets the device act as a forward proxy, a post-auth OS command injection (7.8), a Zip Slip in the Appliance Management Console leading to RCE (7.2), and a stored XSS. SonicWall reports no evidence of in-the-wild exploitation, but earlier SMA1000 flaws in the same product line were exploited.

On 2026-10-06/07 SonicWall published advisory SNWLID-2026-0017 covering four vulnerabilities in the SMA1000 series (models SMA 6210, 7210 and 8200v, physical and virtual). SSL-VPN services on SonicWall firewalls and the SMA 100 Series are not affected.

CVE-2026-102255 (CVSS 10.0, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H; CWE-918, CWE-441) is a pre-authentication SSRF in the SMA1000 Appliance WorkPlace interface. An 'unintended alternate access path' allows the device to act as a forward proxy, so an unauthenticated remote attacker can make the appliance issue requests and reach internal functionality without credentials. CVE-2026-102256 (CVSS 7.8, CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H; CWE-78) is a post-authentication OS command injection that lets an authenticated administrator execute arbitrary OS commands. CVE-2026-102257 (CVSS 7.2, CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H; CWE-22) is a Zip Slip in the Appliance Management Console (AMC): a specially crafted archive extracts files outside the intended destination directory, resulting in remote code execution. CVE-2026-102258 is a post-auth stored XSS in the AMC letting an authenticated administrator run arbitrary JavaScript; the vendor advisory rates it 5.5 while NVD lists CVSS 6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N; CWE-79).

Vulnerable builds are 12.4.3-03526 and earlier and 12.5.0-02952 and earlier; fixed builds are 12.4.3-03670 or later and 12.5.0-03082 or later, delivered via the MySonicWall portal. No workaround exists. The September 2026 builds (12.4.3-03526 / 12.5.0-02952), which fixed the previously exploited CVE-2026-83548 / CVE-2026-83549, do NOT address these flaws, so a fresh upgrade is required. SonicWall states there is no evidence of exploitation in the wild; no public PoC, IOCs, or threat-actor attribution are stated in the sources. Credits: Benoit Sevens (Anthropic) for the SSRF and command injection; Brian Mariani via Trend Micro ZDI (ZDI-CAN-28924) for the Zip Slip; DigitalCanion SA for the XSS.

Defender context: the SMA1000 line has been a repeated target. SonicWall disclosed an unauthenticated SSRF (CVE-2026-15409, CVSS 10.0) and an AMC command injection (CVE-2026-15410, CVSS 7.2) on 2026-07-14, both added to CISA KEV as exploited, and a September SSRF (CVE-2026-83548) plus command injection (CVE-2026-83549) also reported as exploited. An SSRF/forward-proxy primitive on an internet-facing remote-access appliance chained with admin-only command injection or Zip Slip is the same pattern, so rapid patching and review of appliance and authentication logs for anomalous requests is warranted.

MITRE ATT&CK techniques used in TL-2026-3022

Execution

T1059 Command and Scripting Interpreter; T1059.004 Command and Scripting Interpreter: Unix Shell; T1059.007 Command and Scripting Interpreter: JavaScript

Persistence

T1078 Valid Accounts

Command and Control

T1090 Proxy

Initial Access

T1190 Exploit Public-Facing Application

Affected products and versions in SonicWall SMA1000 Four Flaws Patched Incl. Critical Pre-Auth

  • SonicWall — SMA1000 (SMA 6210, SMA 7210, SMA 8200v)
    Vulnerable versions: 12.4.3-03526 and earlier; 12.5.0-02952 and earlier
    Fixed in: 12.4.3-03670 and later; 12.5.0-03082 and later

Remediation for SonicWall SMA1000 Four Flaws Patched Incl. Critical Pre-Auth

Patches

  • SMA1000 12.4.3-03670 or later
  • SMA1000 12.5.0-03082 or later

Immediate actions

  • Upgrade SMA 6210/7210/8200v to 12.4.3-03670 or later, or 12.5.0-03082 or later, via the MySonicWall portal
  • Do not assume the September builds (12.4.3-03526 / 12.5.0-02952) are sufficient; they do not fix these CVEs
  • Review appliance and authentication logs for anomalous requests, including requests the appliance originates to internal ranges

Workarounds

  • None available per SonicWall

Longer-term hardening

  • Restrict the AMC management interface to a dedicated management network
  • Apply egress filtering on the appliance to limit reachable internal endpoints
  • Monitor SonicWall PSIRT for further SMA1000 advisories given repeated 2026 exploitation of this product line

CVEs associated with SonicWall SMA1000 Four Flaws Patched Incl. Critical Pre-Auth

CVE-2026-102255, CVE-2026-102256, CVE-2026-102257, CVE-2026-102258

Weaknesses (CWE) in SonicWall SMA1000 Four Flaws Patched Incl. Critical Pre-Auth

CWE-918, CWE-441, CWE-78, CWE-22, CWE-79

Timeline of SonicWall SMA1000 Four Flaws Patched Incl. Critical Pre-Auth

  • SonicWall disclosed SMA1000 SSRF CVE-2026-15409 (CVSS 10.0) and AMC command injection CVE-2026-15410 (CVSS 7.2) under advisory SNWLID-2026-0008; both confirmed exploited in the wild per Sophos and added to CISA KEV the same day
  • SonicWall published SNWLID-2026-0016 fixing pre-auth SSRF CVE-2026-83548 (CVSS 10.0) and AMC command injection CVE-2026-83549 (CVSS 7.8), confirmed exploited in the wild, in builds 12.4.3-03526 and 12.5.0-02952; previously vulnerable builds were 12.4.3-03453 and 12.5.0-02835 and older
  • CVE-2026-83548 added to CISA KEV at 18:00 UTC per CraftedSignal, with a recommended remediation action date of 2026-09-05
  • SonicWall published advisory SNWLID-2026-0017 for four SMA1000 vulnerabilities; fixed builds 12.4.3-03670 and 12.5.0-03082
  • Cyber Security News reported the patches; SonicWall states no evidence of in-the-wild exploitation and no workaround exists
  • NVD published CVE-2026-102255, CVE-2026-102256, CVE-2026-102257 and CVE-2026-102258

Sources cited for SonicWall SMA1000 Four Flaws Patched Incl. Critical Pre-Auth

Detection coverage for TL-2026-3022

As of 2026-10-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3022 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
12 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats