Product Notice: SMA 1000 Series affected by Multiple Vulnerabilities (SNWLID-2026-0017)

Overview

  • CVE-2026-102255: Server-Side Request Forgery – CVSS Score: 10.0 (Critical)
  • CVE-2026-102256: Remote Code Execution – CVSS Score: 7.8 (High)
  • CVE-2026-102257: Zip Slip Path Traversal – CVSS Score: 7.2 (High)
  • CVE-2026-102258: Stored Cross-Site Scripting – CVSS Score: 5.5 (Medium)

SonicWall Secure Mobile Access 1000 Series 12.4.3 and 12.5.0 firmware (see impacted versions) are affected by multiple vulnerabilities.   

IMPORTANT: There is no evidence that these vulnerabilities are being exploited in the wild.

These vulnerabilities are unrelated to any other reported vulnerability on other SonicWall products.

Product Impact 

Please review the table below to see the products and their versions that are impacted:

Impacted Product(s) 

Impacted Versions (platform-hotfix)

SMA 1000 (6210, 7210, 8200v - all hypervisors) 

12.4.3-03526 (and older versions)

12.5.0-02952 (and older versions)

Remediation 

Impacted Product(s) 

Impacted Versions (platform-hotfix)

Fixed Version 

SMA 1000 (6210, 7210, 8200v - all hypervisors)  

12.4.3-03526 (and older versions)

12.5.0-02952 (and older versions)

12.4.3-03670 (and higher versions) 

12.5.0-03082 (and higher versions) 

All organizations with deployments of SMA1000 appliances (whether virtual or physical) on affected versions should upgrade to the latest hotfix version.

SonicWall strongly advises Secure Mobile Access customers on affected versions follow the guidance provided. 

Related Information

  • Previous Alert
    Product Notice: SMA 1000 Series affected by Multiple Vulnerabilities (SNWLID-2026-0016)
    Read More