A Zip Slip vulnerability in the in the SMA1000 Appliance Management Console (AMC) interface allows an attacker to extract files outside the intended destination directory using a specially crafted archive, resulting in remote code execution.
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0017
https://www.helpnetsecurity.com/2026/10/07/sonicwall-fixes-pre-auth-ssrf-flaw-in-sma-1000-appliances-cve-2026-102255/
https://thehackernews.com/2026/10/sonicwall-patches-cvss-100-pre.html
https://securityaffairs.com/200569/security/sonicwall-fixes-max-severity-pre-auth-flaw-in-sma1000-appliances.html
https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-94326
Source: Mitre, NVD
Published: 2026-10-07
Updated: 2026-10-08
Base Score: 8.3
Vector: CVSS2#AV:N/AC:L/Au:M/C:C/I:C/A:C
Severity: High
Base Score: 7.2
Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.00652