SonicWall SMA1000 SSRF flaw (CVE-2026-102255)
Vulnerability
Summary
Hide ▲
Show ▼
SonicWall released hotfixes for CVE-2026-102255, a maximum-severity SSRF flaw in SMA1000 appliances that can let remote unauthenticated attackers make the device issue requests on their behalf. The issue affects the SMA1000 6210, 7210, and 8200v models and creates a path to internal functionality and unauthorized operations. SonicWall said there is no evidence of exploitation in the wild so far, but it urged customers to install the fixed release version.
Related Happenings
SonicWall SMA1000 hotfix advisory
Advisory/Mitigation
H score58
First: 02.09.2026 09:39
Last: 02.09.2026 09:39
Sources 1
About this happening:
SonicWall has confirmed active exploitation of SMA1000 zero-days and released hotfixes for affected appliances. The attack chain involves CVE-2026-83548 in the A...
SonicWall SMA1000 hotfix advisory
Advisory/MitigationAbout this happening: SonicWall has confirmed active exploitation of SMA1000 zero-days and released hotfixes for affected appliances. The attack chain involves CVE-2026-83548 in the A...
SonicWall SMA1000 zero-day exploitation wave (CVE-2026-15409, CVE-2026-15410)
Exploitation Wave
H score24
First: 03.08.2026 13:39
Last: 03.08.2026 13:39
Sources 1
About this happening:
SonicWall SMA1000 is in an active exploitation wave involving CVE-2026-15409 and CVE-2026-15410, with unauthenticated access to restricted services and root esca...
SonicWall SMA1000 zero-day exploitation wave (CVE-2026-15409, CVE-2026-15410)
Exploitation WaveAbout this happening: SonicWall SMA1000 is in an active exploitation wave involving CVE-2026-15409 and CVE-2026-15410, with unauthenticated access to restricted services and root esca...
INC Ransomware campaign expands across multiple victims
Campaign
H score43
First: 03.08.2026 13:39
Last: 03.08.2026 13:39
Sources 1
About this happening:
The INC Ransomware operation has accelerated its SonicWall SMA1000 exploitation and leak-site pressure, expanding impact across multiple victims in several countri...
INC Ransomware campaign expands across multiple victims
CampaignAbout this happening: The INC Ransomware operation has accelerated its SonicWall SMA1000 exploitation and leak-site pressure, expanding impact across multiple victims in several countri...
CISA KEV catalog addition for SonicWall SMA 1000 flaws
Public Sector Action
H score34
First: 15.07.2026 08:30
Last: 15.07.2026 08:30
Sources 1
About this happening:
CISA added CVE-2026-15409 and CVE-2026-15410 affecting SonicWall SMA 1000 appliances to the Known Exploited Vulnerabilities (KEV) catalog on July 14, 2026,...
CISA KEV catalog addition for SonicWall SMA 1000 flaws
Public Sector ActionAbout this happening: CISA added CVE-2026-15409 and CVE-2026-15410 affecting SonicWall SMA 1000 appliances to the Known Exploited Vulnerabilities (KEV) catalog on July 14, 2026,...
SonicWall SMA1000 SSRF and code injection flaws (multiple vulnerabilities)
Vulnerability
H score48
First: 15.07.2026 00:23
Last: 15.07.2026 00:23
Sources 1
About this happening:
SonicWall SMA1000 vulnerabilities CVE-2026-15409 and CVE-2026-15410 were exploited as zero-days against Secure Mobile Access VPN appliances, with SonicWall rel...
SonicWall SMA1000 SSRF and code injection flaws (multiple vulnerabilities)
VulnerabilityAbout this happening: SonicWall SMA1000 vulnerabilities CVE-2026-15409 and CVE-2026-15410 were exploited as zero-days against Secure Mobile Access VPN appliances, with SonicWall rel...
Latest development: 03.08.2026 13:39
SonicWall patched CVE-2026-15409 and CVE-2026-15410 on July 14, 2026, and CISA added both flaws to the Known Exploited Vulnerabilities (KEV) catalog the same day after the SMA1000 issues had already been abused in the wild.
Timeline
-
07.10.2026 14:37 2 articles · 2h ago
SonicWall releases hotfixes for SMA1000 SSRF flaw
Mitigation Patch UpdateSonicWall released hotfixes for CVE-2026-102255, a maximum-severity server-side request forgery flaw in the Appliance WorkPlace interface of SMA1000 6210, 7210, and 8200v appliances, and urged customers to upgrade to the fixed release version because a remote unauthenticated attacker could direct the appliance to issue requests on their behalf and reach internal functionality.
Show sources
- SonicWall warns of max severity SSRF flaw in SMA1000 gateways — www.bleepingcomputer.com — 07.10.2026 14:37
- SonicWall warns of max severity SSRF flaw in SMA1000 gateways — www.bleepingcomputer.com — 07.10.2026 14:37