Executive Summary

On October 6th, 2026, SonicWall disclosed a critical vulnerability in its SMA1000 series remote access appliances. Tracked as CVE-2026-102255, the flaw lets an unauthenticated, remote attacker abuse a flaw in the Work Place interface to make the appliance perform unauthorized operations.

SMA1000 appliances give remote users access to corporate networks and sit directly on the network edge. Threat actors exploited earlier server-side request forgery flaws in the same Work Place interface as zero-days, which SonicWall disclosed in July and September 2026. The 12.5.0 build that fixed the September flaws is listed as affected by this new one.

SonicWall reports no evidence of exploitation, and no public proof-of-concept (PoC) is known at the time of writing. Given prior zero-day exploitation of this interface, Beazley Security expects threat actors will work quickly to develop exploits. Beazley Security recommends affected organizations apply available fixes as soon as possible.

Affected Systems or Products

Product

Affected Versions

Fixed Versions

SonicWall SMA1000 series (6210, 7210, 8200v), 12.4.3 branch

12.4.3-03526 (platform-hotfix) and earlier

12.4.3-03670 (platform-hotfix) and later

SonicWall SMA1000 series (6210, 7210, 8200v), 12.5.0 branch

12.5.0-02952 (platform-hotfix) and earlier

12.5.0-03082 (platform-hotfix) and later

Mitigations / Workarounds

SonicWall advises SMA1000 customers to upgrade to the fixed platform hotfix for their release branch, and the upgrade also addresses the three post-authentication flaws. SonicWall states that SSL-VPN running on SonicWall firewalls is not affected. Reporting on the bulletin also lists the SMA 100 series as not affected.

If patching cannot be immediately applied, the following may help to temporarily reduce risk:

  • Where business requirements allow, restrict access to the Work Place interface to known source networks or address ranges.

  • Confirm the Appliance Management Console (AMC) is not reachable from the internet and is limited to trusted administrative networks.

  • Monitor SMA1000 appliances for unexpected administrative activity, configuration changes, or outbound connections until the fixed hotfix is installed.

Patches

Organizations that installed 12.5.0-02952 to remediate the September 2026 zero-day exploitation should note that this build is now listed as affected and must be upgraded again.

SonicWall has released fixed platform hotfixes 12.4.3-03670 and 12.5.0-03082, available to customers through MySonicWall. SonicWall's advisory SNWLID-2026-0017 also lists the fixed builds for each branch.

Technical Details

CVE-2026-102255 is a pre-authentication server-side request forgery (SSRF) flaw in the SMA1000 Work Place interface, the user-facing portal of the appliance. SonicWall attributes it to an unintended alternate access path that lets the appliance act as a forward proxy. It classifies the flaw as both SSRF and an unintended proxy vulnerability. By sending requests through this path, an unauthenticated attacker can direct the appliance to issue requests on the attacker's behalf, reach internal functionality that is not meant to be exposed, and perform unauthorized operations.

Exploitation requires only network access to the Work Place interface and no credentials or user interaction are needed. SonicWall has not published further technical detail or stated what internal services the path can reach. No researcher credit is published at the time of writing, and no public PoC is known.

SonicWall's description of CVE-2026-102255 closely mirrors its description of CVE-2026-83548, an SSRF in the same interface caused by an unintended alternate access path. SonicWall has not said whether the new flaw is a variant or bypass of that fix. The same bulletin also fixes three post-authentication flaws: an OS command injection (CVE-2026-102256), a Zip Slip path traversal in the AMC that leads to code execution (CVE-2026-102257), and a stored cross-site scripting flaw in the AMC (CVE-2026-102258).

The Work Place interface has been targeted repeatedly in recent campaigns. On September 1st, 2026, SonicWall disclosed CVE-2026-83548, a pre-authentication SSRF in the Work Place interface, and CVE-2026-83549, a post-authentication OS command injection, as zero-days under active exploitation. CISA added both to its Known Exploited Vulnerabilities (KEV) catalog on September 2nd, 2026, and attackers chained the flaws to achieve unauthenticated remote code execution.

How Beazley Security is responding

Beazley Security is monitoring client perimeter devices through our Exposure Management Platform to identify impacted devices and support organizations in remediation of any issues found.

We are also conducting threat hunts across our MDR environment to detect potential exploitation attempts against our clients.

If you believe your organization may have been impacted by this vulnerability and need support, please contact our Incident Response team.