Critical Vulnerability in SonicWall SMA1000 Series
8 October 2026
SonicWall has released security updates to address a critical vulnerability in the SMA1000 series appliances. Users and administrators of affected products are advised to update to the latest version immediately.
Background
SonicWall has released security updates to address a critical vulnerability (CVE-2026-102255) affecting the SMA 1000 series appliances.
This vulnerability has a Common Vulnerability Scoring System (CVSS v3.1) score of 10.0 out of 10.
Impact
Successful exploitation of this vulnerability could allow a remote unauthenticated attacker to direct the appliance to issue requests on their behalf and access internal functionality and perform unauthorised operations.
Affected Products
This vulnerability affects the following SonicWall SMA 1000 models:
12.4.3-03526 (platform-hotfix) and older versions
12.5.0-02952 (platform-hotfix) and older versions
It does not affect the SMA 100 Series product line or SSL-VPN running on SonicWall firewalls.
Recommendations
Users and administrators of affected products are advised to update to platform-hotfix versions 12.4.3-03453 or 12.5.0-02835, or later releases, immediately.
References
https://nvd.nist.gov/vuln/detail/cve-2026-102255 (opens in new tab)
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0017 (opens in new tab)
