News · Science & Technology

SonicWall warns of max severity SSRF flaw in SMA1000 gateways

SonicWall warns of max severity SSRF flaw in SMA1000 gateways

SonicWall released hotfixes for a maximum-severity server-side request forgery flaw in its SMA1000 series appliances. The vulnerability is tracked as CVE-2026-102255. It matters because remote attackers without privileges can exploit it through a low-complexity attack, potentially reaching internal appliance functions. The flaw affects the Appliance WorkPlace interface on SMA1000 models 6210, 7210, and 8200v. SonicWall told customers to upgrade virtual or physical appliances to the specified fixed release. The fix is intended to close an unintended alternate access path that lets attackers direct the appliance to make requests. SonicWall said there is no evidence that the addressed vulnerabilities are being exploited in the wild. However, Shadowserver tracks more than 400 Internet-exposed SMA1000 appliances, and the company warned customers to patch because attackers frequently target these enterprise remote-access gateways.

Based on reporting by Bleeping Computer

What happened to the SonicWall SMA1000 appliances, and what fixes did SonicWall release?

SonicWall released hotfixes for a maximum-severity server-side request forgery flaw in its SMA1000 series appliances. The vulnerability is tracked as CVE-2026-102255. It matters because remote attackers without privileges can exploit it through a low-complexity attack, potentially reaching internal appliance functions.

The flaw affects the Appliance WorkPlace interface on SMA1000 models 6210, 7210, and 8200v. SonicWall told customers to upgrade virtual or physical appliances to the specified fixed release. The fix is intended to close an unintended alternate access path that lets attackers direct the appliance to make requests.

SonicWall said there is no evidence that the addressed vulnerabilities are being exploited in the wild. However, Shadowserver tracks more than 400 Internet-exposed SMA1000 appliances, and the company warned customers to patch because attackers frequently target these enterprise remote-access gateways.

What is a server-side request forgery (SSRF) vulnerability?

Server-side request forgery, or SSRF, is a vulnerability in which an attacker tricks a server into sending a request to a chosen destination. The server becomes a proxy for the attacker. This matters because servers often have access to internal functions or networks that are not directly reachable from the Internet.

In the SonicWall case, the attacker abuses an unintended alternate access path in the Appliance WorkPlace interface. The appliance then issues requests on the attacker’s behalf. SonicWall said this could let a remote, unauthenticated attacker reach internal functionality and perform unauthorized operations.

SSRF does not necessarily mean the attacker logs in normally. The vulnerable server performs the action instead. SonicWall has released hotfixes for the affected SMA1000 models and said there is currently no evidence these vulnerabilities are being exploited in the wild. Patching blocks the abused path.

Which SMA1000 models are affected, and which SonicWall products are not affected?

CVE-2026-102255 was found in the Appliance WorkPlace interface of three SMA1000 models: 6210, 7210, and 8200v. These appliances are enterprise-grade secure remote-access gateways, so a flaw in their interface can create a serious route toward protected functions.

The affected product scope is specific. SonicWall identified the SMA1000 6210, 7210, and 8200v models as vulnerable. The issue stems from an unintended alternate access path in the Appliance WorkPlace interface, rather than the entire SonicWall product range.

The SMA 100 Series product line is not affected. SSL-VPN running on SonicWall firewalls is also not affected. SonicWall released hotfixes for the vulnerable SMA1000 appliances and advised users of those devices to upgrade to the mentioned fixed release version.

How many Internet-exposed SMA1000 appliances does Shadowserver currently track?

Shadowserver currently tracks over 400 SMA1000 appliances that are exposed to the Internet. That number shows how many devices are visible online, not how many remain vulnerable. The article notes that some of the tracked appliances may already have been patched.

Internet exposure matters because the reported flaw can be exploited remotely without privileges. An exposed Appliance WorkPlace interface may therefore be reachable by attackers scanning or targeting public-facing systems. CVE-2026-102255 is a low-complexity SSRF vulnerability in affected SMA1000 appliances.

SonicWall has urged customers to install its hotfixes and upgrade to the fixed release. The company said there is no evidence that the addressed vulnerabilities are being exploited in the wild. Still, the number of exposed appliances helps explain why prompt patching is important.

What could an unauthenticated attacker do by exploiting this flaw?

The flaw could let a remote attacker who has no account or privileges direct the SMA1000 appliance to issue requests on the attacker’s behalf. This is the core danger of the reported SSRF weakness. The appliance performs the request, rather than the attacker connecting directly to the target function.

SonicWall said the attacker could use an unintended alternate access path in the Appliance WorkPlace interface. By abusing that path, the attacker could potentially reach internal functionality and perform unauthorized operations. The attack is described as low complexity, meaning it does not require elaborate conditions.

The affected models are SMA1000 6210, 7210, and 8200v. SonicWall released hotfixes and advised customers to upgrade virtual or physical appliances. It said there is currently no evidence that the vulnerabilities addressed in the release are being exploited in the wild.

Why are SMA1000 vulnerabilities especially attractive to attackers targeting governments, managed service providers, and large companies?

Attackers find SMA1000 vulnerabilities attractive because these appliances provide secure remote access for government agencies, managed service providers, and large corporations. They help deliver VPN access to internal applications and corporate networks. A weakness in such a gateway can affect an organization’s main remote-access boundary.

The current flaw is especially concerning because it is remotely exploitable without privileges and has low complexity. An attacker could abuse the Appliance WorkPlace interface to make the appliance issue requests, reach internal functionality, and perform unauthorized operations. That combination makes the gateway a valuable target.

The article gives a wider warning. Threat actors have exploited several SMA1000 vulnerabilities in zero-day attacks since the year began. Earlier campaigns installed Sou5, OrangeTail, and RootRun malware, while newer attacks chained zero-days for remote code execution. CISA has added 19 SonicWall vulnerabilities to its exploited-flaw list.

How do secure remote-access gateways and VPNs connect outside users to internal company applications and networks?

Secure remote-access gateways sit between outside users and an organization’s internal applications or networks. They provide a controlled entry point for people working remotely or connecting from outside. VPN technology creates an authenticated connection through that gateway, allowing approved users to reach permitted resources.

In the article’s context, SMA1000 appliances are used by government agencies, managed service providers, and large corporations to provide VPN access to internal apps and corporate networks. A user connects to the gateway, and the gateway handles access to the protected destination. This keeps the internal resources behind the remote-access service rather than directly exposed.

The arrangement also makes the gateway important to defend. If its interface has a flaw, an attacker may try to use the gateway itself as a path toward internal functionality. In this case, SonicWall described an SSRF weakness that could make the appliance issue requests for an unauthenticated attacker.

Key Facts:

📌 SonicWall released hotfixes for maximum-severity CVE-2026-102255.

📌 The flaw affects SMA1000 Appliance WorkPlace interfaces.

📌 SonicWall urged virtual and physical appliance users to upgrade.

📌 SSRF tricks a server into sending requests chosen by an attacker.

📌 The server may reach internal functionality unavailable to the attacker.

📌 SonicWall linked CVE-2026-102255 to an alternate access path.

📌 SMA1000 models 6210, 7210, and 8200v are affected.

More on JupiteX