SonicWall fixes critical SSRF flaw in SMA1000 appliances
SonicWall has issued urgent hotfixes for a critical server-side request forgery (SSRF) vulnerability in its SMA1000 series appliances used for secure remote access to corporate networks. The flaw, rated with the highest severity, could let unauthenticated attackers exploit an access path in the portal to send unauthorized requests inside the network. There is currently no evidence of active exploitation. The company urges immediate updates.
- CVE-2026-102255 affects SMA1000 6210, 7210, and 8200v models
- Attackers could exploit it without authentication
- No evidence of in-the-wild exploitation so far
- Hotfixes are available; prompt update recommended
- Other SonicWall products are not affected
Sources covering this
More in Cybersecurity
Four states sue TP-Link over router security claims
Florida and three other US states have filed lawsuits against TP-Link, alleging the company misled consumers about its routers' security…
Outlook will block MSIX file attachments in November
Microsoft will begin blocking .msix and .msixbundle attachments in Outlook on the web and the new Outlook for Windows starting in November.
Major software vendors patch critical vulnerabilities
Cisco Talos researchers reported multiple vulnerabilities in products from Microsoft, Adobe, Apple, and Foxit.
PoeLLM malware builds botnet targeting AI services
Researchers have identified malware named PoeLLM that has compromised over 3,400 servers since April by targeting open-source AI services.