Skip to content
Brief Security & Trust ·

SonicWall fixes top-severity flaw in SMA1000 remote access gateways

SonicWall reports no exploitation yet, but attackers often target these gateways.

In brief
  • SonicWall released hotfixes on Tuesday for a maximum-severity flaw, CVE-2026-102255, in SMA1000 6210, 7210 and 8200v appliances.
  • SonicWall has no evidence of exploitation, but BleepingComputer says attackers often target these gateways.

BleepingComputer reported on 7 October 2026 that SonicWall has released hotfixes for a maximum-severity flaw, CVE-2026-102255, in its SMA1000 remote access gateways. The bug is in the Appliance WorkPlace interface of the 6210, 7210 and 8200v models. SonicWall released the fixes on Tuesday. It said SMA 100 Series devices and SSL-VPN on its firewalls are not affected.

SonicWall said the flaw is a side route into the appliance that was never meant to be open. Someone with no login could use it to make the appliance send requests for them, and reach internal functions. BleepingComputer said such attacks are low in complexity. SonicWall said it has no evidence that any flaw fixed in this release is being exploited. Shadowserver tracks over 400 internet-exposed SMA1000 appliances, though some may be patched.

The exposure lies in the gateway's trusted position. BleepingComputer said government agencies, managed service providers and large firms use these devices for VPN access to internal apps and networks, and that attackers often target them. It said CISA linked two July SMA1000 zero-days to ransomware gangs. So SonicWall's no-evidence statement is a snapshot, not a guarantee. Buyers can ask: how many do we run, which face the internet, and who owns patching?

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: BleepingComputer.