
🚨 SONICWALL PATCHES CVSS 10.0 UNAUTHENTICATED SSRF IN SMA1000 REMOTE-ACCESS GATEWAYS (CVE-2026-102255) SonicWall released platform hotfixes on October 6, 2026 for a maximum-severity server-side request forgery flaw in its SMA1000 secure remote access appliances. • CVE: CVE-2026-102255 (advisory SNWLID-2026-0017), CVSS 3.0 10.0 • Affected: Appliance WorkPlace interface on SMA1000 6210, 7210 and 8200v running 12.4.3-03526 or 12.5.0-02952 platform-hotfix and older • Fixed: 12.4.3-03670 and 12.5.0-03082 platform-hotfix or later • Impact: a remote, unauthenticated attacker could make the appliance send requests on their behalf, reach internal functionality and perform unauthorized operations • Same advisory: three post-auth flaws (CVE-2026-102256 RCE, CVE-2026-102257 Zip Slip, CVE-2026-102258 stored XSS) • Not affected: SMA 100 series and SSL-VPN on SonicWall firewalls ⚠️ Analyst Note: SonicWall says there is no evidence of exploitation in the wild, and the CVE is not in CISA KEV at handoff. SMA1000 appliances have been exploited as zero-days before (CVE-2025-23006 in January 2025), so treat this as a priority patch for any internet-facing appliance. Official: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0017 #DDW #DarkWeb #CyberSecurity #SonicWall #CVE #PatchNow
