hacker-news · Crawled Oct 7, 2026

SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

Read original article ↗

AI Summary

SonicWall has patched four vulnerabilities in its SMA1000 appliances, the most severe being a pre-authentication server-side request forgery (SSRF) flaw tracked as CVE-2026-102255 with a CVSS score of 10.0. This SSRF vulnerability exists in the WorkPlace portal and could allow unauthenticated attackers to send requests through the appliance to access internal functionality and perform unauthorized operations. The other three flaws require authentication and include an OS command injection, a Zip Slip vulnerability, and a stored cross-site scripting (XSS) issue. SonicWall has not observed exploitation in the wild for these newly patched flaws, but notes this is the third time in 2026 a CVSS 10.0 pre-auth SSRF flaw has been fixed in WorkPlace.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.