SonicWall’s latest critical flaw indicates a security pattern, not another one-off bug
SonicWall has disclosed yet another critical flaw in one of its core products.

SonicWall has disclosed yet another critical flaw in one of its core products.
The short version
- CVE-2026-102255 , rated 10 in severity, the highest possible on the Common Vulnerability Scoring System (CVSS), is a pre-authentication server-side request forgery (SSRF) vulnerability in the SMA1000 Appliance Work Place interface.
- An unintended access path could allow attackers to order the appliance to issue requests on their behalf and gain access to internal functions to perform unauthorized actions.
- At the same time, the cybersecurity company also disclosed three other vulnerabilities of lesser severity impacting the SMA1000, and “strongly advises” customers using the appliances to upgrade to the fixed release version.
What happened
SonicWall said there is no evidence as yet that the critical vulnerability is being exploited in the wild. In an SSRF attack, “an unintended alternate access path lets an unauthenticated attacker steer the appliance into internal functionality and perform unauthorized operations,” Dickson noted.
Why it matters
“The damage also does not stay in the box.
Summary by Nerd News Network. Read the full article at Network World via the links above and below.
