# SonicWall SMA1000 patches RCE and SSRF flaws

Published: 2026-10-07 · Severity: high · Sectors: technology
Canonical: https://vorant.io/reports/0df0c91e-f62c-598e-92d4-81f58f21709d/sonicwall-sma1000-patches-rce-and-ssrf-flaws

> CERT-FR warns multiple SonicWall SMA1000 vulnerabilities, including RCE and SSRF, echo flaw combos actively exploited earlier in 2026.

CERT-FR issued an advisory covering multiple vulnerabilities in SonicWall Secure Mobile Access (SMA1000) products, affecting versions 12.5 prior to 12.5.0-03082 and versions prior to 12.4.3-03670. The flaws include remote code execution, server-side request forgery (SSRF), and indirect remote code injection (XSS), tracked as CVE-2026-102255 through CVE-2026-102258.

While SonicWall has not reported active exploitation of these specific CVEs, CERT-FR highlights that similar vulnerability combinations on this same product line—where an SSRF flaw bypasses authentication to facilitate an otherwise authenticated RCE—have been actively exploited multiple times earlier in 2026, as referenced in prior CERT-FR alerts (CERTFR-2026-ALE-006 and CERTFR-2026-ALE-009). This pattern raises concern that the newly disclosed flaws could follow a similar exploitation path once technical details become available or are reverse-engineered.

Defenders running SonicWall SMA1000 appliances should apply the vendor's patches as a priority, referencing SonicWall's security bulletin SNWLID-2026-0017. Given the product's history of being targeted via authentication-bypass-plus-RCE chains, organizations should treat this as a high-priority patching action even absent confirmed in-the-wild exploitation of these specific CVEs.

## Mentioned in this report

- Vulnerabilities: CVE-2026-102255, CVE-2026-102256, CVE-2026-102257, CVE-2026-102258

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1275

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/0df0c91e-f62c-598e-92d4-81f58f21709d/sonicwall-sma1000-patches-rce-and-ssrf-flaws.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
