SonicWall has issued hotfixes to address four vulnerabilities in its SMA1000 appliances, crucial tools enabling remote access to company networks. Among these, a particularly severe server-side request forgery (SSRF) flaw, identified as CVE-2026-102255, stands out with a critical CVSS score of 10.0. This vulnerability allows attackers to exploit an unintended access path in the WorkPlace portal, potentially facilitating unauthorized operations without needing login credentials.

The affected models include SMA1000 models 6210, 7210, and 8200v, specifically versions 12.4.3-03526 and 12.5.0-02952. SonicWall had initially identified these versions as the remedy for previously exploited flaws. Appliances running these versions require the new hotfix, which is available through the MySonicWall portal. Installation of the hotfix will necessitate a system restart, and no alternative workaround has been provided.

In addition to CVE-2026-102255, there are three other flaws that require authentication to exploit. Two of these occur within the Appliance Management Console (AMC), a crucial component for administrators. It is notable that this is the third instance this year of SonicWall addressing SSRF flaws in the WorkPlace portal.

The discovery of the most recent vulnerabilities was credited to external researchers, with Benoît Sevens of Anthropic and Brian Mariani of DigitalCanion SA being acknowledged for their contributions. SonicWall has not provided specific guidance on whether these vulnerabilities are being actively exploited but encourages users to apply the patches promptly.