
Max-severity SonicWall SMA1000 flaw is patched; attempts seen
The CVE-2026-102255 flaw needs no password. A lab saw attack attempts against a decoy, and SonicWall has not confirmed real-world exploitation.
SonicWall released patches on Oct. 6 for its SMA1000 appliances, including the one that fixes CVE-2026-102255, according to SonicWall's advisory SNWLID-2026-0017. The flaw requires no username or password, and BleepingComputer calls it maximum severity.
It is an SSRF (*server-side request forgery*): the device makes internal requests on behalf of whoever asks it to. It sits in Appliance WorkPlace, the web portal remote employees use to reach their organization's network.
The four key facts about the vulnerability:
- CVE: CVE-2026-102255.
- Product: SMA1000 gateways, models 6210, 7210 and 8200v. The SMA 100 series and SonicWall firewalls are not affected, according to Help Net Security.
- Version: the outlets consulted do not list the affected versions. The fixed ones are 12.4.3-03670 and later, and 12.5.0-03082 and later.
- Patch: yes, available since Oct. 6.
On Oct. 7, SonicWall said there was no evidence that any of the fixed flaws was being exploited in the wild. Later, Ryan Dewhurst of the firm Previdian told BleepingComputer that its honeypot network (decoy machines set up to attract attackers) recorded attempts consistent with this flaw. Previdian does not know whether any would have succeeded. That is the only sign of exploitation, and it has not been confirmed on a real device.
Shadowserver, which tracks exposed devices, counts more than 400 SMA1000 units reachable from the internet. It is unknown how many are decoys or have already installed the patch.
Three other flaws in the same release, CVE-2026-102256, CVE-2026-102257 and CVE-2026-102258, do require authentication. Two earlier SMA1000 flaws were exploited as zero-days this year, according to Help Net Security, which is why this finding is being watched closely.
The action falls to whoever administers the device: install the fixed version. The sources do not mention an alternative mitigation. Still pending is for SonicWall to publish the affected versions and the CVSS score in its advisory, which could not be consulted.



