Vulnerability Bulletin TLP WHITE: Hotfixes Released for SonicWall SMA 1000 Series Appliances

SonicWall has issued security updates to address four vulnerabilities affecting its Secure Mobile Access (SMA) 1000 series appliances, highlighted by a maximum-severity Server-Side Request Forgery (SSRF) flaw tracked as CVE-2026-102255.

Exploitation of this vulnerability allows unauthenticated, remote attackers to bypass access controls and force the appliance to execute unauthorized requests against internal services. While SonicWall reports no active exploitation in the wild at this time, immediate application of official vendor hotfixes is strongly recommended due to high adversary interest in edge remote-access devices.

Health-ISAC provides this information to increase situational awareness and encourage organizations to assess their risk exposure to the vulnerabilities.

Additional Info

Analysis:

SonicWall has disclosed multiple security flaws in its Secure Mobile Access (SMA) 1000 series gateways, led by CVE-2026-102255, a critical Server-Side Request Forgery vulnerability carrying a maximum severity rating. The root cause stems from an unintended alternate access path flaw in the appliance's user-facing Appliance WorkPlace interface. Alongside this critical flaw, SonicWall patched three additional vulnerabilities, including a post-authentication OS command injection bug (CVE-2026-102256), an authenticated path traversal flaw (CVE-2026-102257), and a cross-site scripting (XSS) vulnerability (CVE-2026-102258) in the Appliance Management Console (AMC).

From an exploitation standpoint, CVE-2026-102255 represents a significant risk because it requires no prior privileges or authentication and exhibits low attack complexity. A remote threat actor can transmit specially crafted HTTP requests directly to the internet-facing Appliance WorkPlace portal, manipulating the gateway into routing requests on the attacker’s behalf. By exploiting implicit network trust in the gateway, attackers can access restricted internal endpoints, interact with backend services, and perform administrative operations typically accessible only to authenticated users.

The vulnerabilities affect both hardware and virtual appliances across the SMA 1000 product line running vulnerable firmware builds, including the SMA 6210, SMA 7210, and SMA 8200v. Conversely, SonicWall confirmed that its SMA 100 series appliances and firewall-hosted SSL-VPN deployments are entirely unaffected by these flaws. Organizations deploying impacted SMA 1000 models should prioritize inventory verification, as exposing these gateways to the internet makes them prime targets for edge network discovery and initial access.

Regarding remediation, SonicWall has released official firmware hotfixes to resolve all four flaws; notably, no documented workarounds or mitigation alternatives are available to neutralize the exposure without upgrading. Although the vendor indicates that there is currently no evidence of active in-the-wild exploitation for CVE-2026-102255, SMA 1000 gateways have been repeatedly targeted by advanced threat actors and ransomware affiliates. Given that threat actors have chained similar SMA 1000 flaws in prior zero-day intrusion campaigns, rapid patching is critical before weaponized exploits emerge.

View the detailed bulletin below.

For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact:

John Riggi

National Advisor for Cybersecurity and Risk, AHA

jriggi@aha.org

(O) +1 202 626 2272