SonicWall patches CVSS 10 pre-login flaw in SMA1000 gateways
EditorialBy TrustList Editorial
It is the third maximum-score, pre-authentication WorkPlace request-forgery flaw SonicWall has fixed this year. Three further SMA1000 bugs were patched in the same hotfixes.
- Cybersecurity
- Vulnerability Management
- Remote Access
- VPN
- +1 more
About SonicWall patches CVSS 10 pre-login flaw in SMA1000 gateways
SonicWall patches CVSS 10 pre-login flaw in SMA1000 gateways
6 October 2026: SonicWall has released hotfixes for four vulnerabilities in its SMA1000 secure remote access appliances. The worst, CVE-2026-102255, is a server-side request forgery flaw in the WorkPlace portal that scores the maximum 10.0 and needs no login. An attacker who can reach the portal could use it to get at internal functionality and carry out unauthorised operations. Reports on the advisory say there is no evidence of active exploitation so far.
Not yet independently verified. SonicWall's advisory page needs a browser to render, so the version and score details come from two trade reports that cite it. Check the advisory before scheduling the change. We will update this when it can be confirmed, and remove this note.
SonicWall published the advisory as SNWLID-2026-0017 on 6 October. The Italian national cybersecurity agency ACN issued its own notice the next day, naming the 6210, 7210 and 8200v models of the SMA1000 series.
The other three flaws need some level of access first:
- CVE-2026-102256: OS command injection leading to code execution, requires an administrator account, CVSS 7.8
- CVE-2026-102257: a Zip Slip path-traversal flaw, requires a login, CVSS 7.2
- CVE-2026-102258: stored cross-site scripting, requires an administrator account, CVSS 5.5
Fixed versions
The hotfixes cover the two release lines that are still supported:
- 12.4.3: versions 12.4.3-03526 and older are affected, 12.4.3-03670 and later are fixed
- 12.5.0: versions 12.5.0-02952 and older are affected, 12.5.0-03082 and later are fixed
Why the repeat matters
Trade coverage points out that this is the third pre-authentication WorkPlace request-forgery flaw with a 10.0 score that SonicWall has patched in 2026. The same portal component has therefore produced a maximum-severity bug three times in one year, and WorkPlace is the user-facing portal of the appliance.
The practical test for a team running SMA1000 is whether the WorkPlace portal answers on a public address. If it does, the pre-login flaw is the one to patch first, and the administrator-level bugs can follow in the same maintenance window. Teams that have not recorded which of the two version lines each appliance runs should read it from the appliance before choosing a hotfix.
Company profile on TrustList: SonicWall
Related on TrustList:
- NetScaler CVE-2026-88771: public exploit turns targeted attacks into mass scanning — patch and hunt now
- Edge devices are attacked first, application servers after the patch
- FBI warns FortiBleed is still hitting exposed FortiGate VPNs
Sources
Categories & features
- Cybersecurity
- Vulnerability Management
- Remote Access
- VPN
- Network Security
TrustList Weekly
The week in software and IT, in one email
The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More CybersecurityThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.