CVE-2026-102255

LOWCVSS 10.0 · CRITICAL

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-441CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 7 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked at 5 mentions on most recent observed day (2026-10-07)
  • 7 total mentions across 2 days

Deep dive

Activity timeline7 mentions / 2d
01345Mentions · 2026-10-06: 2Mentions · 2026-10-07: 510-0610-07
Referenced assets3 URLs
Full discourse7 posts
  • Daily CyberSecurity@Daily_CyberSec

    SonicWall SMA1000 vulnerability CVE-2026-102255 (CVSS 10) allows pre-auth SSRF. Three more flaws fixed. Upgrade to 12.5.0-03082 now. #SonicWall #SMA1000 #CVE2026102255 #CVE2026102256 #SSRF #RemoteAccess #VPN #Vulnerability https://securityonline.info/sonicwall-sma1000-vulnerability-cve-2026-102255/

    02072392
    13.0K followersView on X
  • Previdian@PrevidianCyber

    A Critical SonicWall SMA1000 vulnerability found by Anthropic has just been patched. CVE-2026-102255 - Pre-authentication SSRF via unintended forward-proxy CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Affected products: SMA1000 Models - 6210, 7210, 8200v Apply latest hotfixes. No evidence of active exploitation yet.

    11120790
    151 followersView on X
  • キタきつね@foxbook

    SonicWall SMA1000 Vulnerability CVE-2026-102255: Critical Pre-Auth SSRF Flaw (SonicWall SMA1000にCVSS 10.0の重大な脆弱性、認証なしで内部機能へのアクセスが可能) #SecurityOnline (Oct 7) https://securityonline.info/sonicwall-sma1000-vulnerability-cve-2026-102255/

    00030313
    5.0K followersView on X
  • Eric Vanderburg@evanderburg

    #SonicWall fixes pre-auth SSRF flaw in SMA 1000 appliances (CVE-2026-102255) securitytc.​com/TVprXK https://t.co/HAa1g8yGs7

    0000153
    43.7K followersView on X
  • Help Net Security@helpnetsecurity

    SonicWall fixes pre-auth SSRF flaw in SMA 1000 appliances (CVE-2026-102255) - https://www.helpnetsecurity.com/2026/10/07/sonicwall-fixes-pre-auth-ssrf-flaw-in-sma-1000-appliances-cve-2026-102255/ - @SonicWall #Enterprise #MSP #SecurityUpdate #Vulnerability #Cybersecurity #CybersecurityNews https://t.co/VNVYfor5b6

    00001177
    60.2K followersView on X
  • zoomeyebot@zoomeyebot

    🚨 SonicWall SMA1000 pre-auth SSRF rated CVSS 10.0 fixed in platform hotfix 12.4.3-03670 Critical Vulnerability Alert! SonicWall SMA1000 is affected by CVE-2026-102255. 🔍 Identify Targets via ZoomEye: Search Dork: app="SonicWall SMA1000" Exposure: 5.5k instances identified globally. ZoomEye Search Link: 👉 https://www.zoomeye.ai/searchResult?q=YXBwPSJTb25pY1dhbGwgU01BMTAwMCI%3D #SonicWall #SMA1000 #SSRF #CVE2026102255 #ZoomEye

    0000133
    25 followersView on X
  • Shah Sheikh@shah_sheikh

    SonicWall fixes pre-auth SSRF flaw in SMA 1000 appliances (CVE-2026-102255): SonicWall has patched four vulnerabilities in its popular Secure Mobile Access (SMA) 1000… www.​helpnetsecurity.​com/2026/10/07/sonicwall-fixes-pre-auth-ssrf-flaw-in-sma-1000-appliances-cve-2026-102255/ https://t.co/Sd1QgA6usD

    0000018
    2.3K followersView on X

Explore more