# SonicWall SMA1000 Four Flaws Patched Incl. Critical Pre-Auth SSRF CVE-2026-102255 (CVSS 10.0)

> SonicWall patched four vulnerabilities in SMA1000 secure-access appliances (SMA 6210, 7210, 8200v): a CVSS 10.0 pre-authentication SSRF in the WorkPlace interface caused by an unintended alternate access path that lets the device act as a forward proxy, a post-auth OS command injection (7.8), a Zip Slip in the Appliance Management Console leading to RCE (7.2), and a stored XSS. SonicWall reports no evidence of in-the-wild exploitation, but earlier SMA1000 flaws in the same product line were exploited.

- **Published:** 2026-10-07T00:00:00Z
- **Last reviewed:** 2026-10-07T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3022
- **ID:** TL-2026-3022
- **Severity:** CRITICAL (CVSS 10)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 12 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-102255, CVE-2026-102256, CVE-2026-102257, CVE-2026-102258

## Description

On 2026-10-06/07 SonicWall published advisory SNWLID-2026-0017 covering four vulnerabilities in the SMA1000 series (models SMA 6210, 7210 and 8200v, physical and virtual). SSL-VPN services on SonicWall firewalls and the SMA 100 Series are not affected.

CVE-2026-102255 (CVSS 10.0, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H; CWE-918, CWE-441) is a pre-authentication SSRF in the SMA1000 Appliance WorkPlace interface. An 'unintended alternate access path' allows the device to act as a forward proxy, so an unauthenticated remote attacker can make the appliance issue requests and reach internal functionality without credentials. CVE-2026-102256 (CVSS 7.8, CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H; CWE-78) is a post-authentication OS command injection that lets an authenticated administrator execute arbitrary OS commands. CVE-2026-102257 (CVSS 7.2, CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H; CWE-22) is a Zip Slip in the Appliance Management Console (AMC): a specially crafted archive extracts files outside the intended destination directory, resulting in remote code execution. CVE-2026-102258 is a post-auth stored XSS in the AMC letting an authenticated administrator run arbitrary JavaScript; the vendor advisory rates it 5.5 while NVD lists CVSS 6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N; CWE-79).

Vulnerable builds are 12.4.3-03526 and earlier and 12.5.0-02952 and earlier; fixed builds are 12.4.3-03670 or later and 12.5.0-03082 or later, delivered via the MySonicWall portal. No workaround exists. The September 2026 builds (12.4.3-03526 / 12.5.0-02952), which fixed the previously exploited CVE-2026-83548 / CVE-2026-83549, do NOT address these flaws, so a fresh upgrade is required. SonicWall states there is no evidence of exploitation in the wild; no public PoC, IOCs, or threat-actor attribution are stated in the sources. Credits: Benoit Sevens (Anthropic) for the SSRF and command injection; Brian Mariani via Trend Micro ZDI (ZDI-CAN-28924) for the Zip Slip; DigitalCanion SA for the XSS.

Defender context: the SMA1000 line has been a repeated target. SonicWall disclosed an unauthenticated SSRF (CVE-2026-15409, CVSS 10.0) and an AMC command injection (CVE-2026-15410, CVSS 7.2) on 2026-07-14, both added to CISA KEV as exploited, and a September SSRF (CVE-2026-83548) plus command injection (CVE-2026-83549) also reported as exploited. An SSRF/forward-proxy primitive on an internet-facing remote-access appliance chained with admin-only command injection or Zip Slip is the same pattern, so rapid patching and review of appliance and authentication logs for anomalous requests is warranted.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1090 Proxy
- T1059.004 Command and Scripting Interpreter: Unix Shell
- T1059.007 Command and Scripting Interpreter: JavaScript
- T1078 Valid Accounts
- T1059 Command and Scripting Interpreter

## Sources

- [SonicWall PSIRT SNWLID-2026-0017](https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0017)
- [SonicWall Patches 4 SMA1000 Flaws, Including Critical Pre-Auth SSRF Rated CVSS 10](https://cybersecuritynews.com/sonicwall-patches-sma1000-flaws/)
- [NVD CVE-2026-102255](https://nvd.nist.gov/vuln/detail/CVE-2026-102255)
- [NVD CVE-2026-102256](https://nvd.nist.gov/vuln/detail/CVE-2026-102256)
- [NVD CVE-2026-102257](https://nvd.nist.gov/vuln/detail/CVE-2026-102257)
- [NVD CVE-2026-102258](https://nvd.nist.gov/vuln/detail/CVE-2026-102258)
- [Sophos: SonicWall SMA1000 vulnerabilities in active exploitation (CVE-2026-15409 / CVE-2026-15410)](https://www.sophos.com/en-us/blog/sonicwall-sma1000-vulnerabilities-in-active-exploitation)
- [Ampcus Cyber: Actively exploited SonicWall SMA1000 flaws, pre-auth SSRF (CVE-2026-83548) and RCE](https://www.ampcuscyber.com/shadowopsintel/actively-exploited-sonicwall-sma1000-flaws-pre-auth-ssrf-cve-2026-83548-and-rce/)
- [CraftedSignal brief: SonicWall SMA1000 SSRF (SNWLID-2026-0016)](https://feed.craftedsignal.io/briefs/2026-09-sonicwall-sma1000-ssrf/)
- [SonicWall Product Notice: SMA 1000 affected by multiple vulnerabilities](https://www.sonicwall.com/support/notices/product-notice-sma-1000-affected-by-multiple-vulnerabilities/kA1VN000000yhi40AA)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3022
