Skip to content
TECH CEO Daily
CybersecuritySecurity Alert

SonicWall SMA1000 flaw rated CVSS 10.0 draws exploitation attempts days after patch

A no-login server-side request forgery bug in SonicWall's SMA1000 remote-access gateways is being probed by attackers, a researcher says, days after the fix shipped.

By · Editor

· 2 min read · Fact-checked

The 60-second brief

  • 1SonicWall patched CVE-2026-102255, a CVSS 10.0 flaw in SMA1000 gateways needing no login, on October 6.
  • 2Researcher Ryan Dewhurst's honeypots detected exploitation attempts, BleepingComputer reported October 9.
  • 3Shadowserver tracks over 400 SMA1000 appliances online; the SMA 100 series is not affected.

The news

Attackers are trying to exploit a maximum-severity flaw in SonicWall's SMA1000 secure remote-access gateways, days after the company released fixes, BleepingComputer reported on October 9. The SonicWall SMA1000 vulnerability, tracked as CVE-2026-102255, carries a CVSS score of 10.0, according to The Hacker News.

SonicWall published its advisory (SNWLID-2026-0017) on October 6. The Hacker News described the bug as a pre-authentication server-side request forgery (SSRF) flaw in the WorkPlace portal. SSRF means an attacker can make the appliance send requests on their behalf; SonicWall's advisory said an unauthenticated remote attacker could potentially direct the appliance to issue such requests, as quoted by BleepingComputer, and The Hacker News said it could let attackers reach internal functionality and perform unauthorized operations.

Affected models are the SMA1000 6210, 7210 and 8200v. Fixed versions are 12.4.3-03670 and later, and 12.5.0-03082 and later; builds 12.4.3-03526 and 12.5.0-02952 and older are vulnerable, according to The Hacker News. The SMA 100 series and SSL-VPN on SonicWall firewalls are not affected.

When the patch shipped, The Hacker News reported no evidence of active exploitation. By October 9, Ryan Dewhurst, founder of Previdian, had detected exploitation attempts on his honeypot network, BleepingComputer reported. The Shadowserver Foundation tracks more than 400 SMA1000 appliances exposed online, though some may be honeypots or already patched, the outlet noted.

The same update fixed three other bugs: CVE-2026-102256, an OS command injection flaw rated 7.8; CVE-2026-102257, a Zip Slip path flaw rated 7.2; and CVE-2026-102258, a stored cross-site scripting bug rated 5.5. Benoît Sevens of Anthropic was credited with finding CVE-2026-102255 and CVE-2026-102256, The Hacker News reported.

The numbers

CVSS score, CVE-2026-102255
10.0
SMA1000 appliances tracked online
400+ (Shadowserver)
Other flaws fixed in same update
3
Advisory date
October 6, 2026

Why CEOs should care

For CISOs and IT leaders, a remote-access gateway sits at the edge of the network and is built to reach internal systems. A no-login flaw there is exactly what intruders look for. Confirm whether you run SMA1000 6210, 7210 or 8200v appliances and update them to 12.4.3-03670 or 12.5.0-03082 or later. If you cannot patch immediately, restrict access to the WorkPlace portal and watch logs for unusual outbound requests from the appliance.

The bundled command-injection flaw rated 7.8 makes speed more important: attackers commonly chain a first foothold with a second bug to gain deeper control. Assume a gateway left unpatched since October 6 may have been probed and check for signs of compromise before declaring it clean.

Boards and risk committees should ask how fast edge devices from vendors such as SonicWall, Citrix and Fortinet are patched once a critical flaw is public, since the gap between fix and attack attempts here was a matter of days.

The bigger picture

Edge appliances keep showing up in attack campaigns because they are internet-facing and trusted inside the network. The SMA1000 case also highlights AI-era vulnerability research: the most severe flaw was credited to a researcher at Anthropic, as more bugs are found faster and attackers move quickly once fixes reveal where to look.

What’s next

Watch whether CISA adds CVE-2026-102255 to its Known Exploited Vulnerabilities catalog, which would set a federal patch deadline, and whether SonicWall updates its advisory to confirm in-the-wild exploitation.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

SonicWallCVE-2026-102255Remote access

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.