SonicWall patches pre-auth SSRF in SMA 1000 (CVE-2026-102255)
SonicWall has fixed four vulnerabilities in its SMA 1000 SSL VPN appliances, including pre-auth SSRF CVE-2026-102255, which lets unauthenticated attackers reach internal functionality. Physical and virtual models 6210, 7210 and 8200v are affected; hotfixes are available in firmware 12.4.3-03670 and 12.5.0-03082 and later. No exploitation has been observed so far.
- CVE-2026-102255 is a pre-auth SSRF in the Work Place interface
- Affected SMA 1000 models: 6210, 7210 and 8200v
- Fixes: firmware 12.4.3-03670 and 12.5.0-03082 and later
- Two similar SMA 1000 SSRF flaws were exploited as zero-days in 2026
Read next
Security