SonicWall’s latest critical flaw indicates a security pattern, not another one-off bug

Tags:

SonicWall has disclosed yet another critical flaw in one of its core products.

CVE-2026-102255, rated 10 in severity, the highest possible on the Common Vulnerability Scoring System (CVSS), is a pre-authentication server-side request forgery (SSRF) vulnerability in the SMA1000 Appliance Work Place interface. An unintended access path could allow attackers to order the appliance to issue requests on their behalf and gain access to internal functions to perform unauthorized actions.

At the same time, the cybersecurity company also disclosed three other vulnerabilities of lesser severity impacting the SMA1000, and “strongly advises” customers using the appliances to upgrade to the fixed release version.

SonicWall said there is no evidence as yet that the critical vulnerability is being exploited in the wild.

However, explained Frank Dickson, principal analyst at Dickson Research, “CVSS only awards a 10.0 when everything goes the attacker’s way.” This flaw, he said, can be accessed over the network, an attack is easy to pull off and needs no credentials or for a user to click anything to succeed.

In an SSRF attack, “an unintended alternate access path lets an unauthenticated attacker steer the appliance into internal functionality and perform unauthorized operations,” Dickson noted. “The damage also does not stay in the box. Scoring calls that a scope change, and it is what separates a 9.8 from a 10.”

David Shipley, CEO of Beauceron Security, agreed. CVE-2026-102255 is rated 10 in severity “because it allows an attacker to completely hijack a security device remotely before any authentication comes into play,” he said.

Giving attackers RCE abilities

The SonicWall Secure Mobile Access (SMA) 1000 series is a line of SSL virtual private network (VPN) gateways based on zero trust principles. The platform enforces policy-based connectivity for hybrid, on-premises, and multi-cloud environments.

It is used by numerous medium and large enterprises, as well as by managed security service providers (MSSPs) and government agencies. The nature of these organizations makes the appliance a prime target for attackers.

The newly-disclosed maximum severity vulnerability, CVE-2026-102255, impacts SMA 1000 Models 6210, 7210, and 8200v running software versions 12.4.3-03526 and 12.5.0-02952 and earlier. The company said the vulnerabilities do not impact SSL-VPN running on SonicWall firewalls or the SMA 100 Series product line. Customers can download the latest platform-hotfix from mysonicwall.com.

The three other vulnerabilities disclosed by SonicWall this week include the 7.8-rated CVE-2026-102256, which could allow a remote authenticated attacker to take over as admin and execute arbitrary OS commands; the 7.2-rated CVE-2026-102257 that could enable path traversal and remote code execution (RCE); and the 5.5-rated CVE-2026-102258, which in “specific conditions” could give a remote authenticated attacker the ability to store and potentially execute arbitrary JavaScript code in the appliance management console.

SonicWall credited researchers from Anthropic, Trend Micro (through the Zero Day Initiative), and DigitalCanion SA for discovering the flaws.

The trust is the point

SonicWall’s SMA appliances have been riddled with vulnerabilities of late, which have been actively exploited by attackers.

For instance, in September, the company reported two major security holes in the 1000 series. CVE-2026-83548, rated 10 on the severity scale, could allow attackers to “gain unauthorized access to sensitive functionality and perform unauthorized operations,” the company reported.

In addition, CVE-2026-83549, rated 7.8 (high) severity, impacted the SMA Appliance Management Console; authenticated attackers could execute arbitrary OS commands as administrator and perform remote code execution. Both flaws have been patched, but SonicWall disclosed that they were being actively targeted by attackers.

And, in July, a pre-authentication forgery flaw in the SMA1000 series (CVE-2026-15409, also rated a 10 in severity) was exploited as a zero-day vulnerability.

In total, over the last four years, the US Cybersecurity and Infrastructure Security Agency (CISA) has added 19 SonicWall vulnerabilities to its list of actively exploited flaws. Thirteen of these have been targeted in ransomware attacks; SonicWall SSL VPN customers bore the brunt of the ransomware attacks. Another notable incident was a security flaw in the company’s cloud backup service that affected all users in September 2025.

A pattern, not bad luck

The SMA 1000 sits on the network edge for the precise reason that it can reach what is behind it, Dickson noted, adding “that trust is the whole point.” SSRF attacks borrow that trust; the attacker asks the appliance to knock on internal doors, and the doors open because the request seems to come from someone the system trusts. From there, the question is what the SSRF attack can reach.

“It is a Trojan horse,” Dickson said. “The hostile request arrives inside a trusted one.”

Two of the other three flaws disclosed this week can lead to RCE; this follows the “exact recipe” from the attacks in July and September, Dickson noted.

SonicWall’s Tuesday advisory lists software versions 12.4.3-03526 and 12.5.0-02952 as affected. Those are the very hotfixes that fixed September’s zero-days, he pointed out.

“A customer who did everything right last month is exposed again today,” he said. The fixed releases are now 12.4.3-03670 and 12.5.0-03082 or later, and the advisory lists no workaround for the bug other than patching.

Dickson’s advice: Verify the full build on every appliance, either physical or virtual. Take the workplace interface and management console off the open internet where possible. If an appliance sat exposed and unpatched during the July or September windows, treat this patch as “the start of an investigation, not the end.” SonicWall’s guidance after previous incidents was to re-image, rotate passwords, and reset time-based one-time passwords (TOTP); this advice still stands.

Furthermore, Dickson noted, “three 10.0 flaws in one interface in about three months is a pattern, not bad luck.”

Still, most major remote access vendors have taken their turn with a compromised product at least once, Ivanti, Fortinet, Citrix, and Cisco among them. “The internet-facing VPN appliance is the Achilles’ heel of the perimeter,” he noted. “Swapping vendors swaps one heel for another.”

Customers should ask SonicWall whether the current vulnerabilities are new bugs, or just incomplete fixes for previous issues, he advised. “Then patch, verify the build, and ask why the same door keeps opening.”

AI agents will replicate the attack

Shipley also pointed out that, because two of the highest-severity vulnerabilities were discovered by Anthropic researchers, “you can bet a whole host of AIs will replicate this attack now that it’s public.”

He advised checking logs and hunting for this entire bug class “deep within your products.”

“If it was found once, it’ll be found again,” he said.

He agreed with Dickson’s advice, adding that customers should not abandon vendors for having critical CVEs; that will just encourage companies to hide the flaws. “Reward them for demonstrating that they fix entire bug classes by avoiding repeat critical CVEs using the same attack techniques,” he said.

Categories

No Responses

Leave a Reply

Your email address will not be published. Required fields are marked *