SonicWall patched a maximum-severity vulnerability, CVE-2026-102255, in its SMA1000 secure remote-access appliances on 6 October, rating it a full 10.0 on the CVSS scale — the highest the system allows. The flaw is a pre-authentication server-side request forgery (SSRF) bug in the appliance's WorkPlace web interface, affecting models 6210, 7210, and 8200v: an attacker who can simply reach the login page, with no username or password required, can trick the appliance into making requests on their own behalf and reaching internal services it was never meant to expose. SonicWall's initial advisory reported no evidence of active exploitation. That changed within days — independent researcher honeypots detected real attack traffic matching the flaw, using crafted requests aimed at the appliance's internal database service, which researchers found was protected only by its default, publicly documented credentials.
This is also the third pre-authentication SSRF disclosed against the SMA1000 line in 2026 alone, following two earlier flaws patched, and actively exploited, in September. Security researchers have started describing the pattern less as a one-off bug and more as a structural weak point in how the WorkPlace interface is built. For any business using an SMA1000 as the gateway its remote staff connect through, that recurring pattern matters as much as any single CVE number: a device patched once this year may already need patching again.
What this means for your business
If your organisation, or an IT provider acting on your behalf, runs a SonicWall SMA1000 appliance for staff remote access, check the firmware version today rather than at the next routine maintenance window — fixed versions are 12.4.3-03670 and 12.5.0-03082 or later. Because exploitation attempts are already active, treat this as urgent, the same way you would treat a live ransomware alert, not as a patch that can wait.
Given this is the third such flaw in the same product line this year, it is worth asking whoever manages the device two follow-up questions: how quickly were the September fixes actually applied, and is there a standing process to check SonicWall's advisories regularly, rather than only when a headline prompts it? A gateway that was patched once and then left alone is exactly the kind of device this pattern keeps finding.