SonicWall SMA1000 SSRF flaw signals broader security pattern
🔒 SonicWall disclosed CVE-2026-102255, a pre-authentication SSRF vulnerability in the SMA1000 Appliance Workplace interface rated CVSS 10.0, allowing attackers to make the appliance issue requests and reach internal functions without credentials. The company also reported three additional, lower-severity flaws and strongly urges customers to upgrade to fixed releases. SonicWall says there's no evidence of active exploitation yet, but experts warn the attack is trivial to execute and could enable remote compromise.
