SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

Executive Summary

SonicWall released hotfixes for four critical flaws in its SMA1000 gateway appliances. The most severe vulnerability, rated CVSS 10.0, allows unauthenticated attackers to send requests through the appliance and reach internal functions, potentially enabling lateral movement. No evidence of exploitation has been reported.


Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-10-07T16:17:44+00:00 - Category: vulnerabilities

Original Description: SonicWall has released hotfixes for four flaws in its SMA1000 appliances, the gateways that give remote workers access to a company's network and applications. The most serious could allow an attacker without a login to send requests through the appliance and reach internal functions. SonicWall rates it 10.0 on the CVSS scale and says it has no evidence that any of the four flaws is being

"You get peace of mind not by thinking about it or imagining it, but by quietening and relaxing the restless mind."

— Remez Sasson
Source: The Hacker News