SonicWall Releases Critical Security Advisory for SMA1000 Series Appliances
Security updates address four vulnerabilities, including a maximum severity unauthenticated SSRF vulnerability
Summary
Security updates address four vulnerabilities, including a maximum severity unauthenticated SSRF vulnerability
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
SonicWall has released a security advisory to address multiple vulnerabilities in SMA1000 Series Appliances.
- CVE-2026-102255 - 'Server-Side Request Forgery (SSRF)' vulnerability - CVSSv3 score: 10.0.
- CVE-2026-102256 - 'OS Command Injection' vulnerability - CVSSv3 score: 7.8.
- CVE-2026-102257 - 'Path Traversal' vulnerability - CVSSv3 score: 7.2.
- CVE-2026-102258 - 'Cross-Site Scripting' vulnerability - CVSSv3 score: 5.5.
Remediation advice
Affected organisations are encouraged to review SonicWall's security advisory SNWLID-2026-0017 and apply the relevant updates as soon as possible.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 8 October 2026 2:53 pm