Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely

    October 8, 2026

    U.S. Investors Want To Up Their Crypto Holdings: Charles Schwab

    October 8, 2026

    Can WarWilding defend Poland’s borders and save Europe’s last ancient forest?

    October 8, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely
    • U.S. Investors Want To Up Their Crypto Holdings: Charles Schwab
    • Can WarWilding defend Poland’s borders and save Europe’s last ancient forest?
    • Outside spending nears $2 billion – and the biggest groups pull further ahead • OpenSecrets
    • The US has backed Libya’s Haftar clan. The UK should not make the same mistake | Libya
    • Amazon is sending Prime class action settlement payments. Are you eligible?
    • Democrats sue US President Trump over taxpayer-funded ad campaign | Donald Trump News
    • The 23 Best Prime Day Deals Under $100 That You Can Still Get (2026)
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, October 8
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 8, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalOct 07, 2026Vulnerability / Network Security

    SonicWall has released hotfixes for four flaws in its SMA1000 appliances, the gateways that give remote workers access to a company’s network and applications. The most serious could allow an attacker without a login to send requests through the appliance and reach internal functions.

    SonicWall rates it 10.0 on the CVSS scale and says it has no evidence that any of the four flaws is being used in attacks.

    The most serious flaw, tracked as CVE-2026-102255, is a server-side request forgery (SSRF) bug in WorkPlace, the portal that SMA1000 users log in to. It exists due to an unintended access path through SonicWall and can be reached before authentication.

    An attacker who abuses that path could “reach internal functionality and perform unauthorized operations,” SonicWall said in its security advisory, dated October 6, without saying which functions.

    Cybersecurity

    All four flaws affect SMA1000 models 6210, 7210 and 8200v on these platform-hotfix versions:

    • Version 12.4.3: 12.4.3-03526 and older versions are affected. 12.4.3-03670 and higher versions are fixed.
    • Version 12.5.0: 12.5.0-02952 and older versions are affected. 12.5.0-03082 and higher versions are fixed.

    The affected versions include 12.4.3-03526 and 12.5.0-02952, which SonicWall named on September 1 as the fix for two flaws it reported as exploited. An appliance still on those versions needs the new hotfix.

    SSL-VPN on SonicWall firewalls and the SMA 100 Series are not affected.

    The hotfix is available from the MySonicWall portal, and the appliance restarts when the installation finishes. No workaround is listed.

    The other three flaws can be used only after logging in. Two of them are in the Appliance Management Console (AMC), where administrators configure the appliance.

    CVE Flaw Where Access needed SonicWall CVSS score
    CVE-2026-102255 Server-side request forgery (SSRF) WorkPlace None 10.0
    CVE-2026-102256 OS command injection that could lead to remote code execution SMA1000 appliance, component not named Administrator login 7.8
    CVE-2026-102257 Zip Slip: an attacker can use a specially made archive to extract files outside the intended folder, which could lead to remote code execution AMC Login 7.2
    CVE-2026-102258 Stored cross-site scripting (XSS) AMC Administrator login 5.5

    It is the third time this year that SonicWall has fixed a 10.0-rated SSRF flaw in WorkPlace that needs no login.

    SonicWall disclosed CVE-2026-15409 and CVE-2026-15410 on July 14, and CVE-2026-83548 and CVE-2026-83549 on September 1. Both times, it said it had investigated attacks exploiting the flaws: “multiple cases” in July and “a case” in September. Each pair consisted of an SSRF flaw that required no login and a second flaw that could allow a logged-in administrator to run commands on the appliance.

    Cybersecurity

    SonicWall’s own staff found both of those pairs. SonicWall credited outside researchers for the four new flaws: Benoît Sevens of Anthropic for CVE-2026-102255 and CVE-2026-102256, and Brian Mariani of DigitalCanion SA for the other two, one of them reported through Trend Micro’s Zero Day Initiative.

    In the July attacks, CVE-2026-15409 allowed an attacker with no login to open a tunnel to services that respond only inside the appliance, according to Rapid7. The attacker could then run commands and use CVE-2026-15410 to gain root access, which is full control of the appliance.

    SonicWall has not said whether the new SSRF flaw can be combined with the other three in the same way.

    In its July and September advisories, SonicWall told customers to check their appliances for indicators of compromise and, if any were found, to re-image or redeploy the appliance, change user and administrator passwords, and reset the TOTP tokens used for one-time login codes. It has given no such instruction for the four new flaws.

    appliances CVSS Flaw Patches PreAuthentication SMA1000 SonicWall SSRF
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely

    Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

    Ransomware recovery CEO charged over secret ransom payments

    Citizen Lab Slams Trump, ‘Techno-Fascist’ Executives

    FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins

    OpenAI Agent Escape Causes Wikimedia Service Outage

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely

    October 8, 2026

    U.S. Investors Want To Up Their Crypto Holdings: Charles Schwab

    October 8, 2026

    Can WarWilding defend Poland’s borders and save Europe’s last ancient forest?

    October 8, 2026

    Outside spending nears $2 billion – and the biggest groups pull further ahead • OpenSecrets

    October 8, 2026
    Latest Posts

    British national shot dead in Kashmir by Pakistani security forces | Kashmir

    August 10, 2026

    Climate change doubled likelihood of Canada’s extreme fire weather, study finds

    August 10, 2026

    Scientists say just 7 days of meditation can rewire your brain

    August 10, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely

    October 8, 2026

    U.S. Investors Want To Up Their Crypto Holdings: Charles Schwab

    October 8, 2026

    Can WarWilding defend Poland’s borders and save Europe’s last ancient forest?

    October 8, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.