SonicWall releases hotfixes for four security flaws in its Secure Mobile Access (SMA) 1000 series appliances. The most severe issue is a pre-authentication server-side request forgery (SSRF) vulnerability that can allow an attacker—without logging in—to direct the appliance to send requests and reach internal functions, potentially enabling unauthorized operations.
Across the outlets, SonicWall and the reporting focus on the impact of remote, unauthenticated access to internal functionality through the gateway. SonicWall rates the critical flaw at 10.0 on the CVSS scale and states there is currently no evidence that the vulnerabilities addressed by the release are being exploited in the wild. The Help Net Security report identifies the key issue as CVE-2026-102255, described in vendor language as enabling the appliance to act on an attacker’s behalf and reach internal capability.
Other coverage reiterates that multiple vulnerabilities are fixed in the SMA1000 series, with the SSRF flaw highlighted as the maximum-severity risk.