CVE-2026-102257

LOWCVSS 7.2 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A Zip Slip vulnerability in the in the SMA1000 Appliance Management Console (AMC) interface allows an attacker to extract files outside the intended destination directory using a specially crafted archive, resulting in remote code execution.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-10-07: 210-07
Referenced assets2 URLs
Full discourse2 posts
  • Dark Web Intelligence@DailyDarkWeb

    🚨 SONICWALL PATCHES CVSS 10.0 UNAUTHENTICATED SSRF IN SMA1000 REMOTE-ACCESS GATEWAYS (CVE-2026-102255) SonicWall released platform hotfixes on October 6, 2026 for a maximum-severity server-side request forgery flaw in its SMA1000 secure remote access appliances. • CVE: CVE-2026-102255 (advisory SNWLID-2026-0017), CVSS 3.0 10.0 • Affected: Appliance WorkPlace interface on SMA1000 6210, 7210 and 8200v running 12.4.3-03526 or 12.5.0-02952 platform-hotfix and older • Fixed: 12.4.3-03670 and 12.5.0-03082 platform-hotfix or later • Impact: a remote, unauthenticated attacker could make the appliance send requests on their behalf, reach internal functionality and perform unauthorized operations • Same advisory: three post-auth flaws (CVE-2026-102256 RCE, CVE-2026-102257 Zip Slip, CVE-2026-102258 stored XSS) • Not affected: SMA 100 series and SSL-VPN on SonicWall firewalls ⚠️ Analyst Note: SonicWall says there is no evidence of exploitation in the wild, and the CVE is not in CISA KEV at handoff. SMA1000 appliances have been exploited as zero-days before (CVE-2025-23006 in January 2025), so treat this as a priority patch for any internet-facing appliance. Official: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0017 #DDW #DarkWeb #CyberSecurity #SonicWall #CVE #PatchNow

    030205.9K
    207.3K followersView on X
  • CCB Alert@CCBalert

    Warning: A critical SSRF vulnerability in #SonicWall SMA1000 lets unauthenticated attackers reach internal functions. #CVE-2026-102255 #CVE-2026-102256 #CVE-2026-102257 #CVE-2026-102258 CVSS(3.0): 10.0. Read the advisory https://ccb.belgium.be/advisories/warning-pre-authentication-server-side-request-forgery-and-post-authentication-remote and #Patch #Patch #Patch

    02001237
    7.3K followersView on X

Explore more