Find notable cyber news and cases, enriched with sources, timelines, and signals.

SonicWall security patch release for CVE-2026-102255

Security Patch Release
First reported
Last updated
Happening score
H score 36
1 unique sources, 1 articles

Summary

Hide ▲

SonicWall released hotfixes for a maximum-severity SSRF flaw in SMA1000 series appliances, reducing exposure for enterprise secure remote access gateways. The release covers CVE-2026-102255 and targets a weakness that remote unauthenticated attackers can abuse in low-complexity attacks.

Related Happenings

SonicWall SMA1000 hotfix advisory

Advisory/Mitigation
H score58 First: 02.09.2026 09:39 Last: 02.09.2026 09:39 Sources 1

About this happening: SonicWall has confirmed active exploitation of SMA1000 zero-days and released hotfixes for affected appliances. The attack chain involves CVE-2026-83548 in the A...

SonicWall SMA1000 zero-day exploitation wave (CVE-2026-15409, CVE-2026-15410)

Exploitation Wave
H score24 First: 03.08.2026 13:39 Last: 03.08.2026 13:39 Sources 1

About this happening: SonicWall SMA1000 is in an active exploitation wave involving CVE-2026-15409 and CVE-2026-15410, with unauthenticated access to restricted services and root esca...

CISA KEV catalog addition for SonicWall SMA 1000 flaws

Public Sector Action
H score34 First: 15.07.2026 08:30 Last: 15.07.2026 08:30 Sources 1

About this happening: CISA added CVE-2026-15409 and CVE-2026-15410 affecting SonicWall SMA 1000 appliances to the Known Exploited Vulnerabilities (KEV) catalog on July 14, 2026,...

SonicWall security patch release for CVE-2026-15409

Security Patch Release
H score54 First: 15.07.2026 00:23 Last: 15.07.2026 00:23 Sources 1

About this happening: SonicWall released hotfix security updates for SMA1000 appliances after confirming active exploitation of CVE-2026-15409 and CVE-2026-15410. The fixes are availabl...

Cisco Secure Firewall Management Center patch release (CVE-2026-20079, CVE-2026-20131)

Security Patch Release
H score58 First: 04.03.2026 21:12 Last: 04.03.2026 21:12 Sources 1

About this happening: Cisco Secure Firewall Management Center (FMC) patch release for CVE-2026-20131 and CVE-2026-20079 addressed CVSS 10 flaws that could let an unauthenticated remot...

Latest development: 20.03.2026 17:09

CISA ordered Federal Civilian Executive Branch (FCEB) agencies to apply security updates for CVE-2026-20131 in Cisco Secure Firewall Management Center (FMC) by Sunday, March 22 after Cisco updated its bulletin on March 18 to warn of active exploitation in the wild. Amazon threat intelligence researchers said Interlock ransomware had been exploiting CVE-2026-20131 as a zero-day since the end of January, and Cisco said the web-based management interface could let an unauthenticated, remote attacker execute arbitrary Java code as root on an affected device.

Timeline

  1. 07.10.2026 14:37 2 articles · 2h ago

    SonicWall releases hotfixes for CVE-2026-102255 in SMA1000 appliances

    Mitigation Patch Update

    SonicWall released hotfixes for maximum-severity CVE-2026-102255 in SMA1000 6210, 7210, and 8200v appliances, urging customers to upgrade to the fixed release version. The SSRF flaw in the Appliance WorkPlace interface can let remote unauthenticated attackers issue requests on their behalf and reach internal functionality, while SonicWall says there is currently no evidence of exploitation in the wild.

    Show sources