What it is
CVE-2026-102255 is an unauthenticated vulnerability affecting SonicWall SMA1000. A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path....
Vulnerability report
SMA1000 Server-Side Request Forgery
SonicWall / SMA1000 · 12.4.3-03526 (platform-hotfix) and older versions
Decision summary
Direct answers before the deeper technical record.
What it is
CVE-2026-102255 is an unauthenticated vulnerability affecting SonicWall SMA1000. A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path....
Is it exploited?
Yes. Previdian sensors observed exploitation attempts with confirmed confidence. Also confirmed by third-party sources.
Who is affected?
SonicWall / SMA1000 12.4.3-03526 (platform-hotfix) and older versions.
What should we do?
Patch immediately, validate internet-facing exposure, and monitor for matching requests.
Overview
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path.
By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations.
Exploitation evidence
Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.
Previdian
Previdian independently recorded this as exploited after first seeing it in honeypot sensors.
Previdian sensor
Previdian first observed exploitation attempts targeting this vulnerability in our honeypot sensors.
Per-source evidence links for KEV attestations are available through the Previdian Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| Previdian Sensors First | 2026-10-09 08:49 UTC |
| BleepingComputer | 2026-10-09 13:21 UTC |
Operational indicators for this CVE are listed under Detection.
Sensor telemetry
Previdian sensors recorded exploitation attempts targeting this vulnerability. The cards and chart show volume, unique attackers, and daily activity.
24
Attempts observed
1
Unique attacker IPs
1
Attacker countries
US
1
Sensors observed
CVE-2026-102255 exploitation attempts over the last 7 days
Daily events observed by Previdian sensors
Updated 09 Oct 2026
First observed 09 Oct 2026 · Last observed 09 Oct 2026
Pro adds sensor region and window summaries. Enterprise adds raw IPs, paths, User-Agents, and payloads.
Detection
Make the evidence actionable in scanner, SOC, and edge-control workflows.
Request targets and User-Agents available in Pro. Callback host details available in Enterprise.
No scanner integrations recorded yet.
Previdian virtual patch guidance is available for this CVE.
Attacker IP indicators observed · available in Pro and Enterprise.
Sensor-derived attacker IP indicators are available to Pro and Enterprise accounts under Detection and through the Pro API.
Learn about Pro API accessCompensating WAF rules for this CVE.
Enterprise feature. Virtual patch rule content and deployable vendor exports (ModSecurity, Cloudflare, AWS WAF) are available to Previdian Enterprise users.
Risk and context
CVSS v3.1
Potential damage if exploited. Separate from whether attackers are using it.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS
0.5%
Estimated chance of exploitation in the next 30 days. Previdian's warning comes from evidence, not this score.
Recent mention · BleepingComputer
Attackers are exploiting a maximum-severity vulnerability in SonicWall SMA1000 appliances (CVE-2026-102255) that was patched on Tuesday, three days ago. [...]
Read full advisoryRecent mention · BleepingComputer
Max severity SonicWall SMA1000 flaw now exploited in attacksBleepingComputer · 09 Oct 2026
Attackers are exploiting a maximum-severity vulnerability in SonicWall SMA1000 appliances (CVE-2026-102255) that was patched on Tuesday, three days ago. [...]
Recent mention · Security Affairs
SonicWall Fixes Max Severity Pre-Auth Flaw in SMA1000 AppliancesSecurity Affairs · 07 Oct 2026
SonicWall patched a CVSS 10 pre-auth SSRF flaw in SMA1000 appliances that could let unauthenticated attackers reach internal functions. SonicWall released hotfixes for four vulnerabilities in its SMA1000 remote access appliances, including a critical flaw tracked as CVE-2026-102255 (CVSS score of 10.0. The issue is a pre-authentication SSRF bug in the WorkPlace portal that could […]
Recent mention · The Hacker News
SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 AppliancesThe Hacker News · 07 Oct 2026
Swati KhandelwalOct 07, 2026Vulnerability / Network Security SonicWall has released hotfixes for four flaws in its SMA1000 appliances, the gateways that give remote workers access to a company's network and applications. The most serious could allow an attacker without a login to send requests through the appliance and reach internal functions. SonicWall rates it 10.0 on the CVSS scale and says it has no evidence that any of the four flaws is being used in attacks. The most serious flaw, tracked as CVE-2026-102255, is a server-side request forgery (SSRF) bug in WorkPlace, the portal that...
Recent mention · Sonicwall PSIRT
SonicWall SMA1000 Series Appliances Affected By Multiple VulnerabilitiesSonicwall PSIRT · 06 Oct 2026
1) CVE-2026-102255 - Pre-authentication SSRF via unintended forward-proxy A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations.CVSS Score: 10.0 CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CWE-918: Server-Side Request Forgery (SSRF) CWE-441: Unintended Proxy or...
Timeline
13:21 UTC
Exploitation attested by an external source
11:40 UTC
Compensating WAF rule available to block exploitation
00:33 UTC
Indicators of compromise recorded
00:33 UTC
Evidence-backed exploitation signal
14:20 UTC
Pro and Enterprise Watch users had 2 days of early warning before Previdian confirmed it as a KEV.
13:07 UTC
Vulnerability disclosed publicly
19:39 UTC
Identifier reserved by the CNA
Pro API
Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
GET /api/v2/pro/kevs/CVE-2026-102255
Free JSON includes basic KEV fields{
"cve_id": "CVE-2026-102255",
"confidence": "Confirmed",
"cvss_score": 10.0,
"cvss_estimated": false,
"epss_score": 0.00477,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": true
},
"sensor_telemetry": { "attempts": 24, "sensors": 1 }
}