Skip to main content
Get facts, not fiction
Published • loading... • Updated

SonicWall Warns of Max Severity SSRF Flaw in SMA1000 Gateways

The company said the bug lets unauthenticated attackers reach internal functions and urged customers to patch four flaws, including two that can lead to remote code execution.

  • On Tuesday, SonicWall released hotfixes for a maximum-severity SSRF vulnerability, CVE-2026-102255, affecting SMA1000 series appliances. The flaw allows unauthenticated remote attackers to reach internal functionality and perform unauthorized operations.
  • This SSRF vulnerability acts as a 'Trojan horse,' analyst Frank Dickson of Dickson Research explained, where hostile requests arrive inside trusted ones. The flaw exploits the SMA1000's network edge role, bypassing authentication remotely.
  • SonicWall disclosed three additional vulnerabilities impacting SMA1000 models 6210, 7210, and 8200v: a 7.8-rated flaw enabling admin takeover, a 7.2-rated path traversal issue, and a 5.5-rated bug allowing arbitrary JavaScript code execution.
  • Experts warn that users who patched previous security holes remain exposed, as new hotfixes target the same vulnerable versions. Dickson advised customers to 'patch, verify the build, and ask why the same door keeps opening.'
  • Dickson warned that 'three 10.0 flaws in one interface in about three months is a pattern, not bad luck.' Anthropic researchers discovered two high-severity flaws, raising concerns that AIs will rapidly replicate these attacks.
Insights by Ground AI

11 Articles

SMA1000 appliances from SonicWall are designed to protect against unauthorized access to the network. However, a critical gap makes this possible.

·Germany
Read Full Article
Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

BleepingComputer broke the news in Melville, United States on Wednesday, October 7, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal