SonicWall SMA1000 patches RCE and SSRF flaws
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
CERT-FR warns multiple SonicWall SMA1000 vulnerabilities, including RCE and SSRF, echo flaw combos actively exploited earlier in 2026.
CERT-FR issued an advisory covering multiple vulnerabilities in SonicWall Secure Mobile Access (SMA1000) products, affecting versions 12.5 prior to 12.5.0-03082 and versions prior to 12.4.3-03670. The flaws include remote code execution, server-side request forgery (SSRF), and indirect remote code injection (XSS), tracked as CVE-2026-102255 through CVE-2026-102258.
While SonicWall has not reported active exploitation of these specific CVEs, CERT-FR highlights that similar vulnerability combinations on this same product line—where an SSRF flaw bypasses authentication to facilitate an otherwise authenticated RCE—have been actively exploited multiple times earlier in 2026, as referenced in prior CERT-FR alerts (CERTFR-2026-ALE-006 and CERTFR-2026-ALE-009). This pattern raises concern that the newly disclosed flaws could follow a similar exploitation path once technical details become available or are reverse-engineered.
Defenders running SonicWall SMA1000 appliances should apply the vendor's patches as a priority, referencing SonicWall's security bulletin SNWLID-2026-0017. Given the product's history of being targeted via authentication-bypass-plus-RCE chains, organizations should treat this as a high-priority patching action even absent confirmed in-the-wild exploitation of these specific CVEs.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1275
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 10,945 reports from 148 sources, 471 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs