{"id":9947,"date":"2026-10-08T03:19:05","date_gmt":"2026-10-08T03:19:05","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9947"},"modified":"2026-10-08T03:19:05","modified_gmt":"2026-10-08T03:19:05","slug":"sonicwalls-latest-critical-flaw-indicates-a-security-pattern-not-another-one-off-bug","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9947","title":{"rendered":"SonicWall\u2019s latest critical flaw indicates a security pattern, not another one-off bug"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column \">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">SonicWall has disclosed yet another critical flaw in one of its core products.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2026-102255\" target=\"_blank\" rel=\"noopener\">CVE-2026-102255<\/a>, rated 10 in severity, the highest possible on the Common Vulnerability Scoring System (CVSS), is a pre-authentication server-side request forgery (SSRF) vulnerability in the SMA1000 Appliance Work Place interface. An unintended access path could allow attackers to order the appliance to issue requests on their behalf and gain access to internal functions to perform unauthorized actions.<\/p>\n<p class=\"wp-block-paragraph\">At the same time, the cybersecurity company also <a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2026-0017\" target=\"_blank\" rel=\"noopener\">disclosed<\/a> three other vulnerabilities of lesser severity impacting the SMA1000, and \u201cstrongly advises\u201d customers using the appliances to upgrade to the fixed release version.<\/p>\n<p class=\"wp-block-paragraph\">SonicWall said there is no evidence as yet that the critical vulnerability is being exploited in the wild.<\/p>\n<p class=\"wp-block-paragraph\">However, explained <a href=\"https:\/\/www.linkedin.com\/in\/frankdickson\/?isSelfProfile=false\" target=\"_blank\" rel=\"noopener\">Frank Dickson<\/a>, principal analyst at Dickson Research, \u201cCVSS only awards a 10.0 when everything goes the attacker\u2019s way.\u201d This flaw, he said, can be accessed over the network, an attack is easy to pull off and needs no credentials or for a user to click anything to succeed.<\/p>\n<p class=\"wp-block-paragraph\">In an SSRF attack, \u201can unintended alternate access path lets an unauthenticated attacker steer the appliance into internal functionality and perform unauthorized operations,\u201d Dickson noted. \u201cThe damage also does not stay in the box. Scoring calls that a scope change, and it is what separates a 9.8 from a 10.\u201d<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.beauceronsecurity.com\/blog\/tag\/David+Shipley\" target=\"_blank\" rel=\"noopener\">David Shipley<\/a>, CEO of Beauceron Security, agreed. CVE-2026-102255 is rated 10 in severity \u201cbecause it allows an attacker to completely hijack a security device remotely before any authentication comes into play,\u201d he said.<\/p>\n<h2 class=\"wp-block-heading\">Giving attackers RCE abilities<\/h2>\n<p class=\"wp-block-paragraph\">The SonicWall Secure Mobile Access (SMA) 1000 series is a line of SSL virtual private network (VPN) gateways based on zero trust principles. The platform enforces policy-based connectivity for hybrid, on-premises, and multi-cloud environments.<\/p>\n<p class=\"wp-block-paragraph\">It is used by numerous medium and large enterprises, as well as by managed security service providers (MSSPs) and government agencies. The nature of these organizations makes the appliance a prime target for attackers.<\/p>\n<p class=\"wp-block-paragraph\">The newly-disclosed maximum severity vulnerability, CVE-2026-102255, impacts SMA 1000 Models 6210, 7210, and 8200v running software versions 12.4.3-03526 and 12.5.0-02952 and earlier. The company said the vulnerabilities do not impact SSL-VPN running on SonicWall firewalls or the SMA 100 Series product line. Customers can download the latest platform-hotfix from mysonicwall.com.<\/p>\n<p class=\"wp-block-paragraph\">The three other vulnerabilities disclosed by SonicWall this week include the 7.8-rated <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2026-102256\" target=\"_blank\" rel=\"noopener\">CVE-2026-102256<\/a>, which could allow a remote authenticated attacker to take over as admin and execute arbitrary OS commands; the 7.2-rated <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2026-102257\" target=\"_blank\" rel=\"noopener\">CVE-2026-102257<\/a> that could enable path traversal and remote code execution (RCE); and the 5.5-rated <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2026-102258\" target=\"_blank\" rel=\"noopener\">CVE-2026-102258<\/a>, which in \u201cspecific conditions\u201d could give a remote authenticated attacker the ability to store and potentially execute arbitrary JavaScript code in the appliance management console.<\/p>\n<p class=\"wp-block-paragraph\">SonicWall credited researchers from Anthropic, Trend Micro (through the Zero Day Initiative), and DigitalCanion SA for discovering the flaws.<\/p>\n<h2 class=\"wp-block-heading\">The trust is the point<\/h2>\n<p class=\"wp-block-paragraph\">SonicWall\u2019s SMA appliances have been riddled with vulnerabilities of late, which have been actively exploited by attackers.<\/p>\n<p class=\"wp-block-paragraph\">For instance, in September, the company reported <a href=\"https:\/\/www.csoonline.com\/article\/4217682\/sonicwall-reports-two-major-security-holes-under-active-exploit-2.html\" target=\"_blank\" rel=\"noopener\">two major security<\/a> holes in the 1000 series. <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2026-83548\" target=\"_blank\" rel=\"noopener\">CVE-2026-83548<\/a>, rated 10 on the severity scale, could allow attackers to \u201cgain unauthorized access to sensitive functionality and perform unauthorized operations,\u201d the <a href=\"https:\/\/www.sonicwall.com\/support\/notices\/product-notice-sma-1000-series-affected-by-multiple-vulnerabilities-snwlid-2026-0016\/kA1VN000002AXmQ0AW\" target=\"_blank\" rel=\"noopener\">company reported<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">In addition, <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2026-83549\" target=\"_blank\" rel=\"noopener\">CVE-2026-83549<\/a>, rated 7.8 (high) severity, impacted the SMA Appliance Management Console; authenticated attackers could execute arbitrary OS commands as administrator and perform remote code execution. Both flaws have been patched, but SonicWall disclosed that they were being actively targeted by attackers.<\/p>\n<p class=\"wp-block-paragraph\">And, in July, a pre-authentication forgery flaw in the SMA1000 series (CVE-2026-15409, also rated a 10 in severity) was exploited as a zero-day vulnerability.<\/p>\n<p class=\"wp-block-paragraph\">In total, over the last four years, the US Cybersecurity and Infrastructure Security Agency (CISA) has added 19 SonicWall vulnerabilities to its <a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=&amp;field_date_added_wrapper=all&amp;items_per_page=All&amp;search=&amp;sort_by=field_date_added&amp;url=&amp;f%5B0%5D=vendor_project%3A839\" target=\"_blank\" rel=\"noopener\">list of actively exploited flaws<\/a>. Thirteen of these have been targeted in ransomware attacks; SonicWall SSL VPN customers bore the brunt of the <a href=\"https:\/\/www.csoonline.com\/article\/4097078\/sonicwall-ransomware-attacks-offer-an-ma-lesson-for-csos.html\" target=\"_blank\" rel=\"noopener\">ransomware attacks<\/a>. Another notable incident was a security flaw in the company\u2019s <a href=\"https:\/\/www.csoonline.com\/article\/4070992\/data-leak-at-sonicwall-affects-all-cloud-backup-customers.html\" target=\"_blank\" rel=\"noopener\">cloud backup service<\/a> that affected all users in September 2025. <\/p>\n<h2 class=\"wp-block-heading\">A pattern, not bad luck<\/h2>\n<p class=\"wp-block-paragraph\">The SMA 1000 sits on the network edge for the precise reason that it can reach what is behind it, Dickson noted, adding \u201cthat trust is the whole point.\u201d SSRF attacks borrow that trust; the attacker asks the appliance to knock on internal doors, and the doors open because the request seems to come from someone the system trusts. From there, the question is what the SSRF attack can reach.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIt is a Trojan horse,\u201d Dickson said. \u201cThe hostile request arrives inside a trusted one.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Two of the other three flaws disclosed this week can lead to RCE; this follows the \u201cexact recipe\u201d from the attacks in July and September, Dickson noted. <\/p>\n<p class=\"wp-block-paragraph\">SonicWall\u2019s Tuesday advisory lists software versions 12.4.3-03526 and 12.5.0-02952 as affected. Those are the very hotfixes that fixed September\u2019s zero-days, he pointed out.<\/p>\n<p class=\"wp-block-paragraph\">\u201cA customer who did everything right last month is exposed again today,\u201d he said. The fixed releases are now 12.4.3-03670 and 12.5.0-03082 or later, and the advisory lists no workaround for the bug other than patching.<\/p>\n<p class=\"wp-block-paragraph\">Dickson\u2019s advice: Verify the full build on every appliance, either physical or virtual. Take the workplace interface and management console off the open internet where possible. If an appliance sat exposed and unpatched during the July or September windows, treat this patch as \u201cthe start of an investigation, not the end.\u201d SonicWall\u2019s guidance after previous incidents was to re-image, rotate passwords, and reset time-based one-time passwords (TOTP); this advice still stands.<\/p>\n<p class=\"wp-block-paragraph\">Furthermore, Dickson noted, \u201cthree 10.0 flaws in one interface in about three months is a pattern, not bad luck.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Still, most major remote access vendors have taken their turn with a compromised product at least once, Ivanti, Fortinet, Citrix, and Cisco among them. \u201cThe internet-facing VPN appliance is the Achilles\u2019 heel of the perimeter,\u201d he noted. \u201cSwapping vendors swaps one heel for another.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Customers should ask SonicWall whether the current vulnerabilities are new bugs, or just incomplete fixes for previous issues, he advised. \u201cThen patch, verify the build, and ask why the same door keeps opening.\u201d<\/p>\n<h2 class=\"wp-block-heading\">AI agents will replicate the attack<\/h2>\n<p class=\"wp-block-paragraph\">Shipley also pointed out that, because two of the highest-severity vulnerabilities were discovered by Anthropic researchers, \u201cyou can bet a whole host of AIs will replicate this attack now that it\u2019s public.\u201d<\/p>\n<p class=\"wp-block-paragraph\">He advised checking logs and hunting for this entire bug class \u201cdeep within your products.\u201d<\/p>\n<p class=\"wp-block-paragraph\">\u201cIf it was found once, it\u2019ll be found again,\u201d he said.<\/p>\n<p class=\"wp-block-paragraph\">He agreed with Dickson\u2019s advice, adding that customers should not abandon vendors for having critical CVEs; that will just encourage companies to hide the flaws. \u201cReward them for demonstrating that they fix entire bug classes by avoiding repeat critical CVEs using the same attack techniques,\u201d he said.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>SonicWall has disclosed yet another critical flaw in one of its core products. CVE-2026-102255, rated 10 in severity, the highest possible on the Common Vulnerability Scoring System (CVSS), is a pre-authentication server-side request forgery (SSRF) vulnerability in the SMA1000 Appliance Work Place interface. An unintended access path could allow attackers to order the appliance to [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9948,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9947","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9947"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9947"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9947\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9948"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9947"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9947"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9947"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}