SonicWall released fixes for four vulnerabilities in SMA 1000 remote access appliances, led by CVE-2026-102255, a critical pre-authentication server-side request forgery and unintended proxy flaw in the Work Place interface. An unauthenticated attacker with network access to that interface could make the appliance issue requests on their behalf, access internal functionality, and perform unauthorized operations without user interaction. The updates also address post-authentication OS command injection, administrator-authenticated path traversal, and administrator-authenticated cross-site scripting. Affected models are 6210, 7210, and 8200v; SonicWall firewall SSL-VPN functionality and SMA 100 Series devices are unaffected.
Organizations should upgrade affected appliances to 12.4.3-03670 or later or 12.5.0-03082 or later. Releases 12.4.3-03526 and earlier and 12.5.0-02952 and earlier remain vulnerable, including the previously patched 12.5.0-02952 build. SonicWall reported no evidence of exploitation of these four flaws, and no public proof of concept was known at publication, but two earlier pre-authentication SSRF vulnerabilities in SMA 1000 were reportedly exploited as zero-days in 2026. Pending patching, organizations should restrict Work Place access, isolate the Appliance Management Console, and monitor for suspicious activity.

Map this exposure pattern across your cloud, code, and identities.
5 events from the most recent confirmed update back to the earliest known activity.
SonicWall disclosed an unintended alternate access path in the SMA1000 Work Place interface that allows unauthenticated attackers to make the appliance issue requests, reach internal functionality, and perform unauthorized operations. Models 6210, 7210, and 8200v are affected, including the previously patched 12.5.0-02952 build.
CISA added CVE-2026-83548 and CVE-2026-83549 to its Known Exploited Vulnerabilities catalog.
SonicWall disclosed Work Place SSRF vulnerability CVE-2026-83548 and post-authentication command injection vulnerability CVE-2026-83549 as actively exploited zero-days. Attackers chained the flaws to achieve unauthenticated remote code execution.
An earlier server-side request forgery vulnerability in the SonicWall SMA1000 Work Place interface was disclosed after being exploited as a zero-day.
SonicWall released platform hotfixes 12.4.3-03670 and 12.5.0-03082 to address CVE-2026-102255 and three additional command injection, path traversal, and cross-site scripting vulnerabilities. SonicWall reported no evidence of exploitation of the four flaws and stated that firewall SSL-VPN functionality and SMA 100 Series devices were unaffected.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
4 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourceacn.gov.it
Open sourcelabs.beazley.security
Open sourcepsirt.global.sonicwall.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.