CVE-2026-102256

LOWCVSS 7.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 appliance which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-10-07: 310-07
Referenced assets3 URLs
Full discourse3 posts
  • Dark Web Intelligence@DailyDarkWeb

    🚨 SONICWALL PATCHES CVSS 10.0 UNAUTHENTICATED SSRF IN SMA1000 REMOTE-ACCESS GATEWAYS (CVE-2026-102255) SonicWall released platform hotfixes on October 6, 2026 for a maximum-severity server-side request forgery flaw in its SMA1000 secure remote access appliances. • CVE: CVE-2026-102255 (advisory SNWLID-2026-0017), CVSS 3.0 10.0 • Affected: Appliance WorkPlace interface on SMA1000 6210, 7210 and 8200v running 12.4.3-03526 or 12.5.0-02952 platform-hotfix and older • Fixed: 12.4.3-03670 and 12.5.0-03082 platform-hotfix or later • Impact: a remote, unauthenticated attacker could make the appliance send requests on their behalf, reach internal functionality and perform unauthorized operations • Same advisory: three post-auth flaws (CVE-2026-102256 RCE, CVE-2026-102257 Zip Slip, CVE-2026-102258 stored XSS) • Not affected: SMA 100 series and SSL-VPN on SonicWall firewalls ⚠️ Analyst Note: SonicWall says there is no evidence of exploitation in the wild, and the CVE is not in CISA KEV at handoff. SMA1000 appliances have been exploited as zero-days before (CVE-2025-23006 in January 2025), so treat this as a priority patch for any internet-facing appliance. Official: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0017 #DDW #DarkWeb #CyberSecurity #SonicWall #CVE #PatchNow

    030205.9K
    207.3K followersView on X
  • CCB Alert@CCBalert

    Warning: A critical SSRF vulnerability in #SonicWall SMA1000 lets unauthenticated attackers reach internal functions. #CVE-2026-102255 #CVE-2026-102256 #CVE-2026-102257 #CVE-2026-102258 CVSS(3.0): 10.0. Read the advisory https://ccb.belgium.be/advisories/warning-pre-authentication-server-side-request-forgery-and-post-authentication-remote and #Patch #Patch #Patch

    02001237
    7.3K followersView on X
  • zoomeyebot@zoomeyebot

    🚨 SonicWall SMA1000 Appliance Hit by Four Critical Flaws (CVE-2026-102255 to CVE-2026-102258) Enabling Pre-Auth SSRF and Post-Auth RCE Critical Vulnerability Alert! SonicWall SMA1000 Appliance is affected by CVE-2026-102256. 🔍 Identify Targets via ZoomEye: Search Dork: app="SonicWall SMA1000" Exposure: 5.5k instances identified globally. ZoomEye Search Link: 👉 https://www.zoomeye.ai/searchResult?q=YXBwPSJTb25pY1dhbGwgU01BMTAwMCI%3D #SonicWall #SMA1000 #CVE2026102256 #SSRF #RCE #PathTraversal #CyberSecurity

    0000040
    25 followersView on X

Explore more