SonicWall released hotfixes for CVE-2026-102255, an unauthenticated server-side request forgery flaw in the Appliance WorkPlace interface of its SMA1000 secure access gateways. A remote attacker with no credentials could use an unintended alternate access path to direct the appliance to issue requests on their behalf, reaching internal functionality and performing unauthorized operations. The flaw affects SMA1000 6210, 7210, and 8200v models and does not impact the SMA 100 series or firewall SSL-VPN. SonicWall says there is no evidence of exploitation yet, but more than 400 internet-exposed SMA1000 appliances are tracked and the line has historically drawn ransomware operators.