Vulnerabilities

Max-severity SonicWall SMA1000 flaw draws exploit attempts

Honeypots record exploitation attempts against CVE-2026-102255, a CVSS 10 SonicWall SMA1000 flaw. September-patched gateways are vulnerable again.

Warning graphic for exploitation attempts against SonicWall SMA1000 flaw CVE-2026-102255

Within days of SonicWall shipping a fix for a maximum-severity flaw in its SMA1000 remote access gateways, honeypots began recording attempts to exploit it. Anyone running these appliances who patched for September’s zero-days is exposed again and needs to act this weekend.

What happened

On Tuesday 6 October 2026 SonicWall published advisory SNWLID-2026-0017, fixing four vulnerabilities in its Secure Mobile Access (SMA) 1000 series. The headline bug, CVE-2026-102255, is a server-side request forgery (SSRF) flaw, reachable before any login, in the Appliance Work Place interface, and the vendor scored it 10.0 on CVSS, the highest rating available. It affects the 6210, 7210 and 8200v models. SonicWall says the SMA 100 range and the SSL-VPN feature built into its firewalls are not affected.

At the time of the advisory SonicWall said it had no evidence of exploitation. That changed quickly. On Friday 9 October Ryan Dewhurst, founder of exploitation intelligence firm Previdian, told BleepingComputer that the company’s honeypot network had picked up requests consistent with an attempt to exploit CVE-2026-102255. Previdian was careful to add that it had not established whether those attempts would have succeeded against a real system, so at this stage what has been observed is hostile probing rather than confirmed compromise. SonicWall had not updated its advisory to flag active exploitation when this article was written, and the flaw does not currently appear in CISA’s Known Exploited Vulnerabilities catalogue.

Shadowserver is tracking more than 400 SMA1000 appliances reachable from the internet, although it is unclear how many of those are already patched or are themselves research honeypots.

The technical picture

SonicWall attributes the bug to “an unintended alternate access path” in the Work Place portal. An unauthenticated attacker who reaches that path can make the appliance send requests on their behalf, which lets them touch internal functions that should never be exposed and carry out operations they are not authorised to perform. SSRF on a perimeter device is particularly unpleasant because the appliance sits in a position of trust: requests it makes to services behind it look legitimate. The vendor’s scoring reflects that, with a scope change in the CVSS vector indicating that the impact extends beyond the vulnerable component itself.

According to Previdian, the traffic it saw was aimed at the same Work Place interface hit by earlier SSRF flaws in July and September, but used a different technique, attempting to reach an internal database service running on the appliance. No public proof of concept had been identified at the time of writing, and SonicWall has not yet released indicators of compromise for it.

The same advisory covers three lower-rated bugs. CVE-2026-102256 (CVSS 7.8) could let an authenticated attacker take over administrative functions and run operating system commands; CVE-2026-102257 (7.2) is a path traversal issue that can lead to remote code execution; and CVE-2026-102258 (5.5) is a stored cross-site scripting flaw in the management console. The discoveries were credited to researchers at Anthropic, Trend Micro’s Zero Day Initiative and DigitalCanion SA.

The detail that should worry administrators most is the affected version range. Builds 12.4.3-03526 and 12.5.0-02952 and earlier are vulnerable, and those are precisely the hotfixes released to close September’s actively exploited zero-days (CVE-2026-83548 and CVE-2026-83549). The fixed releases are 12.4.3-03670 and 12.5.0-03082 or later, and SonicWall lists no workaround.

Timeline of SonicWall SMA1000 vulnerabilities from the July 2026 zero-days to the October fix for CVE-2026-102255 and exploitation attempts

Why it matters for UK organisations

The SMA1000 is an enterprise-grade gateway, used by larger companies, public sector bodies and, crucially, managed security service providers to give staff and engineers access to internal applications. That last group is the real concern for the UK. A compromised gateway at a provider can become a route into every customer network that provider looks after, and the supply chain risk posed by MSPs is exactly why the Cyber Security and Resilience Bill proposes bringing many of them into regulatory scope.

This is also the third maximum-severity issue in the same SMA1000 interface in roughly three months. July’s pair of zero-days (CVE-2026-15409 and CVE-2026-15410) were abused for weeks to plant custom malware, and CISA later linked some of that activity to ransomware groups. Over the past four years CISA has listed 19 SonicWall flaws as exploited, 13 of them tied to ransomware. With FortiBleed still causing trouble for Fortinet customers and a run of Citrix NetScaler bugs this autumn, UK security teams are dealing with sustained pressure on every major brand of edge appliance.

For organisations working towards or holding Cyber Essentials, the scheme expects high and critical security updates for in-scope devices to be applied within 14 days of release. A CVSS 10.0 flaw in a remote access gateway, now attracting exploitation attempts, should be handled far faster than that.

Expert view

In my experience, SSRF on an edge device is routinely underestimated because the bug class sounds less dramatic than straightforward code execution. When we test remote access estates, the gateway is almost always trusted far more than it deserves by the systems behind it, and anything that lets an outsider borrow that trust is a skeleton key. Frank Dickson of Dickson Research put the pattern bluntly to CSO Online, calling three 10.0 flaws in one interface “a pattern, not bad luck”.

The version overlap is the part I would escalate. Teams that responded promptly to September’s emergency have every reason to believe their appliances are current, and that confidence is now misplaced. I would also take seriously the point that a vulnerability found once by an automated or AI-assisted process is likely to be rediscovered by attackers using similar tooling. Probing was reported within about three days of the advisory here, and that gap is shrinking across the industry.

It is worth keeping perspective. Honeypot hits are not breaches, and Previdian has been clear about what it does not yet know. But waiting for confirmed victims before patching an internet-facing VPN gateway has rarely ended well.

What to do now

  1. Inventory every SMA1000 appliance, physical and virtual, and check the full build string. Anything on 12.4.3-03526, 12.5.0-02952 or earlier is vulnerable, including appliances patched in September.
  2. Upgrade to 12.4.3-03670 or 12.5.0-03082 or later from mysonicwall.com immediately. There is no workaround (Cyber Essentials: security update management).
  3. Reduce exposure. Restrict the Appliance Management Console to trusted administrative networks and question whether the Work Place portal needs to face the whole internet (Cyber Essentials: firewalls and secure configuration).
  4. Review logs on the appliance and on internal services it can reach for unusual requests since 6 October, and keep an eye on SonicWall’s advisory for indicators.
  5. Close out earlier waves. If an appliance sat on the internet without fixes while the July or September campaigns were running, treat it as potentially compromised: follow SonicWall’s earlier guidance to re-image, rotate passwords and reset TOTP secrets.
  6. Ask your suppliers. If an MSP connects to your network through SMA1000, request evidence of its current build and its compromise checks rather than a yes or no answer.

Bottom line

CVE-2026-102255 is a textbook edge-device emergency: maximum severity, no authentication needed, no workaround, and attackers sniffing around within days. The added twist is that last month’s fix is this month’s vulnerable build. Patch now, verify the version on every box, and lock down management interfaces, because exploitation attempts rarely stay attempts for long.

Sources