Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical Pre‑Auth SSRF Flaw (CVE‑2026‑102255) in SonicWall SMA1000 Appliances Allows Unauthenticated Access

SonicWall disclosed a CVSS 10.0 pre‑authentication SSRF vulnerability (CVE‑2026‑102255) affecting SMA1000 models, enabling unauthenticated attackers to reach internal functions. The flaw underscores the need for continuous control verification and audit‑ready evidence around network perimeter protections.

LiveThreat™ Intelligence · 📅 October 08, 2026· 📰 securityaffairs.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
securityaffairs.com

Critical Pre‑Auth SSRF Vulnerability (CVE‑2026‑102255) in SonicWall SMA1000 Appliances

What It Is – SonicWall disclosed a pre‑authentication Server‑Side Request Forgery (SSRF) flaw in the WorkPlace portal of its SMA1000 remote‑access appliances. The vulnerability (CVE‑2026‑102255) carries a CVSS 10.0 rating, meaning an unauthenticated attacker could direct the appliance to issue arbitrary internal requests and perform unauthorized operations.

Exploitability – No public exploitation has been observed, but the flaw is trivial to weaponize once a vulnerable version is reachable. A vendor‑issued hotfix is available; no workaround exists.

Affected Products – SMA1000 models 6210, 7210, 8200v running firmware 12.4.3‑03526 (or older) and 12.5.0‑02952 (or older). Other SMA‑100 series products and SSL‑VPN functionality are not impacted.

Why It Matters for Trust & Control Assurance

  • Highlights the need for continuous verification that unauthenticated traffic cannot reach internal management functions – a core access‑control assurance objective.
  • Demonstrates how a single unpatched flaw can break the audit trail of “defensible evidence” that an organization’s perimeter controls are effective.
  • Provides a concrete control‑gap example that can be mapped to multiple frameworks (e.g., NIST CSF PR.AC‑1) to show remediation readiness to enterprise buyers.

Recommended Actions

  • Deploy the SonicWall SMA1000 hotfixes immediately via the MySonicWall portal.
  • Conduct post‑patch testing to confirm the WorkPlace portal no longer accepts unauthenticated SSRF requests.
  • Update your control inventory, capture remediation evidence, and align the fix with your framework of record for audit readiness.

Source: SecurityAffairs article

📰 Original Source
https://securityaffairs.com/200569/security/sonicwall-fixes-max-severity-pre-auth-flaw-in-sma1000-appliances.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →