The SonicWall SMA1000 flaw tracked as CVE-2026-102255 carries the maximum severity score of 10.0, and it can be reached without logging in. SonicWall patched it on October 6, 2026. By October 9, one research firm's honeypots had recorded exploitation attempts, although no successful compromise has been confirmed. If your business, or your IT provider, runs an SMA 6210, 7210 or 8200v, it needs the hotfix now.
Most small businesses do not own an SMA1000, which is an enterprise remote access gateway. The broader lesson still applies to almost every business in the US and Canada: the box that lets staff connect from home sits on the open internet, and attackers check it first.
What Is the SonicWall SMA1000 Flaw?
CVE-2026-102255 is a server-side request forgery (SSRF) flaw in the Appliance Work Place interface, the portal SMA1000 users log in to. In SonicWall's words, quoted by BleepingComputer, a remote unauthenticated attacker "could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations." In plain English, the appliance can be tricked into acting as the attacker's messenger inside the network.
The key facts from SonicWall's advisory, as reported by The Hacker News, SC Media and BleepingComputer:
- Severity: CVSS 10.0, with no login required.
- Affected models: SMA 6210, 7210 and 8200v.
- Affected versions: 12.4.3-03526 and 12.5.0-02952 and older.
- Fixed versions: 12.4.3-03670 and higher, and 12.5.0-03082 and higher.
- Not affected: the SMA 100 Series and SSL-VPN on SonicWall firewalls.
- Workaround: none listed. Installing the hotfix restarts the appliance.
One detail catches teams out. The Hacker News notes that the affected versions include the ones SonicWall released on September 1 to fix two earlier flaws it reported as exploited. An appliance that was patched last month is vulnerable again.
Is CVE-2026-102255 Being Exploited?
Exploitation attempts have been seen, but no compromise has been confirmed. SonicWall said in its October 6 advisory that it had no evidence any of the four flaws it fixed was being used in attacks, according to The Hacker News. On October 9, Previdian founder Ryan Dewhurst told BleepingComputer that the firm's honeypots, decoy systems built to attract attackers, had detected attempts consistent with the flaw.
Be precise about what that means:
- What was seen: crafted requests aimed at the appliance's internal database service, reported by both BleepingComputer and SC Media.
- What was not established: Dewhurst said Previdian had not yet established whether those attempts would have compromised any systems.
- Government status: SC Media reported that, as of Friday, October 9, CISA had not added the flaw to its Known Exploited Vulnerabilities catalog.
Security leaders quoted by SC Media argued that teams should not wait for that listing. That is a reasonable call when the device controls who gets into the network.
Why Do Remote Access Appliances Keep Getting Hit?
Because they are on the internet by design and they hold the keys to the inside. This is the third 10.0-rated SSRF flaw in the Work Place interface that needs no login in 2026, after July and September, according to both The Hacker News and SC Media. BleepingComputer reported that CISA linked some of the July attacks to ransomware gangs.
The pattern is not unique to SonicWall. BleepingComputer counts 19 SonicWall flaws added to CISA's catalog of actively exploited vulnerabilities over four years, 13 of them flagged as used by ransomware. In June, the FortiBleed campaign exposed credentials tied to 73,932 Fortinet firewall and SSL VPN URLs, as we covered in our FortiBleed analysis. Different vendors and different weaknesses, but the same target: the front door for remote staff.
Speed makes it worse. As we noted in our piece on how the CVE-to-exploit window dropped to about 10 hours, exploit-intelligence data suggests attackers now move from disclosure to a working exploit in hours. Here, the honeypot attempts came three days after the advisory.
Why Doesn't MFA Stop This?
Because the attacker never logs in. Multi-factor authentication protects accounts, and this flaw sits in front of the login. Jason Soroko of Sectigo told SC Media that the flaw lets an attacker reach internal functions without logging in, so MFA does not close this route: the appliance that controls remote access can itself become the entry point. That is different from FortiBleed, where stolen passwords were the problem and MFA was the main fix.
This is why security teams talk about not trusting the network edge on its own. A zero-trust approach treats every user and device as potentially untrusted, regardless of location or connection, so a compromised gateway does not automatically open everything behind it.
What Should SMB Leaders Ask Their IT Provider?
Ask for an inventory, not reassurance. Every internet-facing device that grants access to your network, including VPN gateways, firewalls and remote access portals, should be listed with its model, current version and the date it was last patched. The checklist below applies whether you run SonicWall, Fortinet, Cisco or anything else.
- Do we run any SonicWall SMA1000 appliance, and is it on 12.4.3-03670, 12.5.0-03082 or later? If yes and not yet patched, plan a short maintenance window. Denis Calderone of Suzu Labs told SC Media the hotfix reboots the appliance and drops all VPN sessions, so it should not be applied over the VPN itself.
- If we cannot patch today, can we take the Work Place interface off the public internet until we do? Experts quoted by SC Media recommended exactly that.
- After patching, did anyone check the logs? Soroko told SC Media that patching "does not establish whether an attacker already gained access."
- What is our list of internet-facing devices, and who watches for advisories on each one? Monthly or quarterly reporting on patching status is standard practice, as our guide to evaluating a managed IT provider explains.
- If the gateway were compromised, what is our first move? Under pressure, the urge to "just get things working again" can destroy evidence, a risk our incident response planning guide covers.
Canadian businesses can map this work to the Canadian Centre for Cyber Security's Baseline Controls on patching and remote access. US businesses can map it to the CIS Controls or, for covered financial firms, the FTC Safeguards Rule.
The Lasting Lesson
The appliance that lets your team work from anywhere also lets anyone on the internet knock. When a flaw in that appliance needs no password, every hour between the advisory and the patch is exposure. The one question to put to your IT lead this week is simple: "List every device we expose to the internet, and tell me how fast each one gets patched when a critical flaw lands."
If you are not sure how your business would answer, start with our free quick security assessment. It takes about five minutes and shows which of 22 security areas need attention first.
This article is intended for general informational purposes only and does not constitute professional security, legal, or compliance advice. Details about CVE-2026-102255 and the reported exploitation attempts are based on SonicWall's advisory and public reporting as of October 10, 2026, and may change as SonicWall, CISA and researchers publish more information. Organizations should consult qualified cybersecurity professionals before acting on any specific indicator of compromise or making operational changes based on this article.