SonicWall security patch release for CVE-2026-102255
Security Patch Release
Summary
Hide ▲
Show ▼
SonicWall released hotfixes for a maximum-severity SSRF flaw in SMA1000 series appliances, reducing exposure for enterprise secure remote access gateways. The release covers CVE-2026-102255 and targets a weakness that remote unauthenticated attackers can abuse in low-complexity attacks.
Related Happenings
SonicWall SMA1000 hotfix advisory
Advisory/Mitigation
H score58
First: 02.09.2026 09:39
Last: 02.09.2026 09:39
Sources 1
About this happening:
SonicWall has confirmed active exploitation of SMA1000 zero-days and released hotfixes for affected appliances. The attack chain involves CVE-2026-83548 in the A...
SonicWall SMA1000 hotfix advisory
Advisory/MitigationAbout this happening: SonicWall has confirmed active exploitation of SMA1000 zero-days and released hotfixes for affected appliances. The attack chain involves CVE-2026-83548 in the A...
SonicWall SMA1000 zero-day exploitation wave (CVE-2026-15409, CVE-2026-15410)
Exploitation Wave
H score24
First: 03.08.2026 13:39
Last: 03.08.2026 13:39
Sources 1
About this happening:
SonicWall SMA1000 is in an active exploitation wave involving CVE-2026-15409 and CVE-2026-15410, with unauthenticated access to restricted services and root esca...
SonicWall SMA1000 zero-day exploitation wave (CVE-2026-15409, CVE-2026-15410)
Exploitation WaveAbout this happening: SonicWall SMA1000 is in an active exploitation wave involving CVE-2026-15409 and CVE-2026-15410, with unauthenticated access to restricted services and root esca...
CISA KEV catalog addition for SonicWall SMA 1000 flaws
Public Sector Action
H score34
First: 15.07.2026 08:30
Last: 15.07.2026 08:30
Sources 1
About this happening:
CISA added CVE-2026-15409 and CVE-2026-15410 affecting SonicWall SMA 1000 appliances to the Known Exploited Vulnerabilities (KEV) catalog on July 14, 2026,...
CISA KEV catalog addition for SonicWall SMA 1000 flaws
Public Sector ActionAbout this happening: CISA added CVE-2026-15409 and CVE-2026-15410 affecting SonicWall SMA 1000 appliances to the Known Exploited Vulnerabilities (KEV) catalog on July 14, 2026,...
SonicWall security patch release for CVE-2026-15409
Security Patch Release
H score54
First: 15.07.2026 00:23
Last: 15.07.2026 00:23
Sources 1
About this happening:
SonicWall released hotfix security updates for SMA1000 appliances after confirming active exploitation of CVE-2026-15409 and CVE-2026-15410. The fixes are availabl...
SonicWall security patch release for CVE-2026-15409
Security Patch ReleaseAbout this happening: SonicWall released hotfix security updates for SMA1000 appliances after confirming active exploitation of CVE-2026-15409 and CVE-2026-15410. The fixes are availabl...
Cisco Secure Firewall Management Center patch release (CVE-2026-20079, CVE-2026-20131)
Security Patch Release
H score58
First: 04.03.2026 21:12
Last: 04.03.2026 21:12
Sources 1
About this happening:
Cisco Secure Firewall Management Center (FMC) patch release for CVE-2026-20131 and CVE-2026-20079 addressed CVSS 10 flaws that could let an unauthenticated remot...
Cisco Secure Firewall Management Center patch release (CVE-2026-20079, CVE-2026-20131)
Security Patch ReleaseAbout this happening: Cisco Secure Firewall Management Center (FMC) patch release for CVE-2026-20131 and CVE-2026-20079 addressed CVSS 10 flaws that could let an unauthenticated remot...
Latest development: 20.03.2026 17:09
CISA ordered Federal Civilian Executive Branch (FCEB) agencies to apply security updates for CVE-2026-20131 in Cisco Secure Firewall Management Center (FMC) by Sunday, March 22 after Cisco updated its bulletin on March 18 to warn of active exploitation in the wild. Amazon threat intelligence researchers said Interlock ransomware had been exploiting CVE-2026-20131 as a zero-day since the end of January, and Cisco said the web-based management interface could let an unauthenticated, remote attacker execute arbitrary Java code as root on an affected device.
Timeline
-
07.10.2026 14:37 2 articles · 2h ago
SonicWall releases hotfixes for CVE-2026-102255 in SMA1000 appliances
Mitigation Patch UpdateSonicWall released hotfixes for maximum-severity CVE-2026-102255 in SMA1000 6210, 7210, and 8200v appliances, urging customers to upgrade to the fixed release version. The SSRF flaw in the Appliance WorkPlace interface can let remote unauthenticated attackers issue requests on their behalf and reach internal functionality, while SonicWall says there is currently no evidence of exploitation in the wild.
Show sources
- SonicWall warns of max severity SSRF flaw in SMA1000 gateways — www.bleepingcomputer.com — 07.10.2026 14:37
- SonicWall warns of max severity SSRF flaw in SMA1000 gateways — www.bleepingcomputer.com — 07.10.2026 14:37