BleepingComputer reported on 7 October 2026 that SonicWall has released hotfixes for a maximum-severity flaw, CVE-2026-102255, in its SMA1000 remote access gateways. The bug is in the Appliance WorkPlace interface of the 6210, 7210 and 8200v models. SonicWall released the fixes on Tuesday. It said SMA 100 Series devices and SSL-VPN on its firewalls are not affected.
SonicWall said the flaw is a side route into the appliance that was never meant to be open. Someone with no login could use it to make the appliance send requests for them, and reach internal functions. BleepingComputer said such attacks are low in complexity. SonicWall said it has no evidence that any flaw fixed in this release is being exploited. Shadowserver tracks over 400 internet-exposed SMA1000 appliances, though some may be patched.
The exposure lies in the gateway's trusted position. BleepingComputer said government agencies, managed service providers and large firms use these devices for VPN access to internal apps and networks, and that attackers often target them. It said CISA linked two July SMA1000 zero-days to ransomware gangs. So SonicWall's no-evidence statement is a snapshot, not a guarantee. Buyers can ask: how many do we run, which face the internet, and who owns patching?