Back to Newsroom
Threat Intel

SonicWall Patches Critical SSRF Flaw in SMA1000 Remote Access Gateways

A maximum-severity SSRF vulnerability in SonicWall's SMA1000 series could let unauthenticated attackers reach internal appliance functions — the latest in a string of flaws hitting these widely deployed VPN gateways.

SonicWall Patches Critical SSRF Flaw in SMA1000 Remote Access Gateways

SonicWall has shipped hotfixes for a maximum-severity server-side request forgery (SSRF) vulnerability affecting its SMA1000 series secure remote access appliances — hardware and virtual gateways widely used by enterprises, government agencies, and managed service providers to broker VPN access into internal networks.

What happened

Tracked as CVE-2026-102255, the flaw lives in the Appliance WorkPlace interface of the SMA1000 6210, 7210, and 8200v models. It stems from an alternate access path that was never meant to be reachable, and because it requires no authentication and is simple to trigger, an attacker who finds it can make the appliance issue requests on their behalf — effectively turning the gateway into a proxy toward functionality and services that should only be reachable internally. The SMA 100 series and SonicWall firewalls' SSL-VPN are not affected.

SonicWall says it hasn't seen the bug exploited yet and released the fix proactively, but given this product line's recent history, that window may not stay open long.

Why it matters

SMA1000 gateways sit at the edge of corporate networks by design, brokering remote access for exactly the kind of organizations attackers most want to reach. Monitoring from Shadowserver currently counts more than 400 of these appliances still exposed directly to the internet, with the largest concentration in the United States.

This isn't a one-off. Earlier this year, two separate SMA1000 zero-days were exploited for weeks to drop custom malware on victim appliances, in intrusions linked to ransomware operators. Just last month, another pair of zero-days was disclosed being chained together for remote code execution on the same product line. Over the past four years, 19 SonicWall vulnerabilities have landed on the US government's catalog of actively exploited flaws — 13 of which were later used in ransomware attacks. SMA1000 devices have become a recurring target, and threat actors appear to be watching this product closely.

What to do

  • Apply SonicWall's hotfix to any SMA1000 6210, 7210, or 8200v appliance immediately — don't wait for a confirmed exploitation report.
  • Inventory internet-facing SMA1000 and other remote-access gateways; anything with a public management or WorkPlace interface should be reviewed and restricted where possible.
  • Treat SMA1000 patching as a standing priority, not a one-time fix — this device line has a track record of repeat zero-days followed by ransomware activity.
  • If you can't patch immediately, restrict access to the WorkPlace interface to trusted networks only and monitor appliance logs for anomalous internal requests.

4tify's monitoring tracks disclosures like this across the gateways and edge devices our clients rely on, so patch windows don't turn into incident timelines.

SHARE