Home / Oct 08, 2026 / Story
0
#3 The Hacker News general October 07, 2026 at 16:17 UTC

SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

By [email protected] (The Hacker News)

AI Summary

SonicWall patched four vulnerabilities in its SMA1000 remote access appliances, including a CVSS 10.0 pre-authentication server-side request forgery (SSRF) flaw that allows unauthenticated attackers to route requests through the gateway to reach internal network functions. SonicWall stated no evidence of exploitation exists for any of the four flaws at time of disclosure. Administrators of SMA1000 series appliances should apply the released hotfixes immediately given the maximum severity rating.

Relevance score: 84.0/100

# More from October 08