The news
Attackers are trying to exploit a maximum-severity flaw in SonicWall's SMA1000 secure remote-access gateways, days after the company released fixes, BleepingComputer reported on October 9. The SonicWall SMA1000 vulnerability, tracked as CVE-2026-102255, carries a CVSS score of 10.0, according to The Hacker News.
SonicWall published its advisory (SNWLID-2026-0017) on October 6. The Hacker News described the bug as a pre-authentication server-side request forgery (SSRF) flaw in the WorkPlace portal. SSRF means an attacker can make the appliance send requests on their behalf; SonicWall's advisory said an unauthenticated remote attacker could potentially direct the appliance to issue such requests, as quoted by BleepingComputer, and The Hacker News said it could let attackers reach internal functionality and perform unauthorized operations.
Affected models are the SMA1000 6210, 7210 and 8200v. Fixed versions are 12.4.3-03670 and later, and 12.5.0-03082 and later; builds 12.4.3-03526 and 12.5.0-02952 and older are vulnerable, according to The Hacker News. The SMA 100 series and SSL-VPN on SonicWall firewalls are not affected.
When the patch shipped, The Hacker News reported no evidence of active exploitation. By October 9, Ryan Dewhurst, founder of Previdian, had detected exploitation attempts on his honeypot network, BleepingComputer reported. The Shadowserver Foundation tracks more than 400 SMA1000 appliances exposed online, though some may be honeypots or already patched, the outlet noted.
The same update fixed three other bugs: CVE-2026-102256, an OS command injection flaw rated 7.8; CVE-2026-102257, a Zip Slip path flaw rated 7.2; and CVE-2026-102258, a stored cross-site scripting bug rated 5.5. Benoît Sevens of Anthropic was credited with finding CVE-2026-102255 and CVE-2026-102256, The Hacker News reported.
The numbers
- CVSS score, CVE-2026-102255
- 10.0
- SMA1000 appliances tracked online
- 400+ (Shadowserver)
- Other flaws fixed in same update
- 3
- Advisory date
- October 6, 2026
Why CEOs should care
For CISOs and IT leaders, a remote-access gateway sits at the edge of the network and is built to reach internal systems. A no-login flaw there is exactly what intruders look for. Confirm whether you run SMA1000 6210, 7210 or 8200v appliances and update them to 12.4.3-03670 or 12.5.0-03082 or later. If you cannot patch immediately, restrict access to the WorkPlace portal and watch logs for unusual outbound requests from the appliance.
The bundled command-injection flaw rated 7.8 makes speed more important: attackers commonly chain a first foothold with a second bug to gain deeper control. Assume a gateway left unpatched since October 6 may have been probed and check for signs of compromise before declaring it clean.
Boards and risk committees should ask how fast edge devices from vendors such as SonicWall, Citrix and Fortinet are patched once a critical flaw is public, since the gap between fix and attack attempts here was a matter of days.
The bigger picture
Edge appliances keep showing up in attack campaigns because they are internet-facing and trusted inside the network. The SMA1000 case also highlights AI-era vulnerability research: the most severe flaw was credited to a researcher at Anthropic, as more bugs are found faster and attackers move quickly once fixes reveal where to look.
What’s next
Watch whether CISA adds CVE-2026-102255 to its Known Exploited Vulnerabilities catalog, which would set a federal patch deadline, and whether SonicWall updates its advisory to confirm in-the-wild exploitation.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error





