SonicWall patches maximum-severity SSRF flaw in SMA1000 gateways

Summary
SonicWall released hotfixes for an unauthenticated SSRF flaw in SMA1000 gateways. The company says it has no evidence of exploitation and urges customers to update affected appliances.
Key points
- CVE-2026-102255 affects the Appliance WorkPlace interface on SMA1000 6210, 7210, and 8200v models.
- Remote attackers without credentials could exploit the flaw to make appliances send requests and reach internal functionality for unauthorized operations.
- SonicWall released hotfixes and advises customers to upgrade affected appliances.
- SonicWall says there is currently no evidence the vulnerability is being exploited in the wild.
- The flaw does not affect the SMA 100 Series or SSL-VPN running on SonicWall firewalls.
- Shadowserver tracks more than 400 internet-exposed SMA1000 appliances, though some may already be patched.
Article Details
- Vulnerability Types
- Server-side request forgery (SSRF)
- Severity
- Maximum severity
- Exploitation Status
- not_reported
- Exploit Availability
- unknown
- Patch Status
- available
MITRE ATT&CK
CVE
CVE-2026-102255Tracked as CVE-2026-102255, the vulnerability was found in the Appliance WorkPlace interface of SMA1000 6210, 7210, and 8200v models, but it does not affect the SMA 100 Series product line or SSL-VPN running onCVE-2026-15409In July, two SMA1000 zero-days (CVE-2026-15409 and CVE-2026-15410) were exploited for weeks to install custom Sou5, OrangeTail, and RootRun malware on vulnerable VPN appliances in attacks that the U.S.CVE-2026-15410In July, two SMA1000 zero-days (CVE-2026-15409 and CVE-2026-15410) were exploited for weeks to install custom Sou5, OrangeTail, and RootRun malware on vulnerable VPN appliances in attacks that the U.S.CVE-2026-83548Last month, SonicWall also warned customers that attackers were chaining two new zero-days (CVE-2026-83548 and CVE-2026-83549) to execute remote code on vulnerable SMA1000 gateways.CVE-2026-83549Last month, SonicWall also warned customers that attackers were chaining two new zero-days (CVE-2026-83548 and CVE-2026-83549) to execute remote code on vulnerable SMA1000 gateways.
Malware
OrangeTailIn July, two SMA1000 zero-days (CVE-2026-15409 and CVE-2026-15410) were exploited for weeks to install custom Sou5, OrangeTail, and RootRun malware on vulnerable VPN appliances in attacks that the U.S.RootRunIn July, two SMA1000 zero-days (CVE-2026-15409 and CVE-2026-15410) were exploited for weeks to install custom Sou5, OrangeTail, and RootRun malware on vulnerable VPN appliances in attacks that the U.S.Sou5In July, two SMA1000 zero-days (CVE-2026-15409 and CVE-2026-15410) were exploited for weeks to install custom Sou5, OrangeTail, and RootRun malware on vulnerable VPN appliances in attacks that the U.S.
Vendors
Products
Industries
Governmentoften target SMA1000 flaws because they affect enterprise-grade secure remote access gateways used by government agencies, Managed Service Providers (MSSPs), and many large corporations to provide VPN access toManaged Service Providers (MSSPs)they affect enterprise-grade secure remote access gateways used by government agencies, Managed Service Providers (MSSPs), and many large corporations to provide VPN access to internal apps and corporate networks.