At a glance:
-
SonicWall released hotfixes on October 6, 2026, for four vulnerabilities affecting SMA1000 secure remote access appliances, including a maximum-severity flaw in the Appliance WorkPlace interface.
-
CVE-2026-102255 allows a remote, unauthenticated threat actor to make the appliance issue requests that can reach internal functionality. SonicWall has reported no evidence of exploitation.
-
Identifying affected SMA1000 appliances, installing the latest hotfix, limiting unnecessary network access, and monitoring traffic originating from the appliances reduces exposure to unauthorized internal requests.
Threat summary
On October 6, 2026, just over a month after addressing two actively exploited SMA1000 vulnerabilities, SonicWall released hotfixes for four additional flaws affecting Secure Mobile Access (SMA) 1000 Series appliances.
The most significant, CVE-2026-102255, is a pre-authentication server-side request forgery (SSRF) vulnerability in the Appliance WorkPlace interface that can be exploited remotely without authentication or user interaction. SonicWall reported no evidence of exploitation at the time of disclosure.
The SMA1000 series is a secure remote access platform used to provide employees, contractors, and partners with access to internal applications from outside the corporate network. The affected products include the SMA 6210 and SMA 7210 hardware appliances and the SMA 8200v virtual appliance, all of which run the SMA1000 software platform.
CVE-2026-102255 affects Appliance WorkPlace, the web portal through which remote users access resources published by the SMA1000 gateway. SonicWall describes the flaw as an unintended alternate access path that allows a remote, unauthenticated attacker to make the appliance issue requests on their behalf. By abusing this behavior, an attacker can reach internal functionality and perform unauthorized operations through the appliance.
Exploitation requires only network access to the Appliance WorkPlace interface. Internally accessible deployments would require an attacker to first obtain access to a network that can reach the appliance.
The vulnerability affects SMA 6210, SMA 7210, and SMA 8200v appliances running platform hotfix 12.4.3-03526 or earlier and 12.5.0-02952 or earlier.
SonicWall fixed the issue in platform hotfixes 12.4.3-03670 and 12.5.0-03082. SMA 100 Series appliances and SSL-VPN functionality on SonicWall firewalls are not affected.
The update also addresses three authenticated vulnerabilities:
-
CVE-2026-102256 is an operating system command injection vulnerability that SonicWall characterizes as remote code execution and requires an administrator account.
-
CVE-2026-102257 is a Zip Slip path traversal vulnerability in the Appliance Management Console that allows a specially crafted archive to place files outside the intended extraction directory and may lead to remote code execution.
-
CVE-2026-102258 is a stored cross-site scripting vulnerability in the Appliance Management Console that requires administrator access.
Analysis
Internet-accessible SMA1000 appliances face the most direct exposure because Appliance WorkPlace is designed to accept connections from remote users and CVE-2026-102255 can be exploited before authentication. Public reporting identified more than 400 internet-exposed SMA1000 appliances at the time of disclosure, although external scanning cannot determine which systems remain vulnerable.
SMA1000 appliances are attractive targets because they sit between remote users and internal applications. Their role requires them to communicate with systems and services that are not intended to be accessible directly from the internet. If an attacker can abuse the appliance to send requests on their behalf, they may be able to interact with functionality that would otherwise be inaccessible from an external network.
SonicWall has not identified the functions involved or disclosed what level of access those operations provide. Publicly available information does not establish administrative access, appliance compromise, or remote code execution through CVE-2026-102255.
The potential impact depends on how the appliance is deployed and what systems it can access. Appliances with connectivity to management interfaces, identity services, application programming interfaces (APIs), or other sensitive resources may present greater opportunities for follow-on activity than deployments with tightly restricted network access. Network segmentation, service-level authentication, and outbound access controls will largely determine how far exploitation can extend beyond the vulnerable component.
While SonicWall has reported no evidence that CVE-2026-102255 is being exploited, threat actors have targeted SMA1000 vulnerabilities repeatedly throughout 2026, including flaws disclosed in July and September that were reported as exploited in the wild. That activity does not indicate exploitation of CVE-2026-102255, but it demonstrates continued attacker interest in internet-accessible remote access infrastructure.
Mitigations
Upgrade affected SMA1000 appliances to platform hotfix 12.4.3-03670 or later or 12.5.0-03082 or later. The update removes the vulnerable request path in Appliance WorkPlace and addresses the additional vulnerabilities included in the advisory.
At the same time, identify all SMA 6210, SMA 7210, and SMA 8200v deployments and verify the complete platform-hotfix version, as organizations that patched for the September SMA1000 vulnerabilities may still be running versions affected by CVE-2026-102255.
Review exposure of the Appliance WorkPlace interface and prioritize systems that are reachable from the internet. Limiting access to authorized users, trusted networks, and approved geographic regions reduces the number of systems able to interact with the vulnerable service.
Identify the internal applications, APIs, management interfaces, identity services, and other resources reachable from each SMA1000 appliance. Restrict outbound connectivity to only the services required for business operations and remote access workflows. This reduces the number of internal systems that could be reached if an attacker successfully abuses the appliance to issue requests on their behalf. Network segmentation between remote access infrastructure and sensitive administrative systems further limits potential follow-on activity.
Monitor Appliance WorkPlace activity, outbound connections originating from SMA1000 appliances, administrative actions, configuration changes, and unusual authentication events. Particular attention should be paid to requests targeting management interfaces or services that are not normally accessed through the appliance. Reviewing these activities can help identify attempts to use the gateway as an intermediary for unauthorized operations and provide early visibility into suspicious behavior