TL;DR
Threat actors are now actively targeting a critical SonicWall SMA1000 vulnerability in the wild. The flaw allows unauthenticated remote attackers to reach internal gateway functions without credentials. Therefore, network administrators must deploy newly released security hotfixes right away to prevent unauthorized access.
- CVE: CVE-2026-102255
- CVSS: 10.0 (Critical Β· CVSSv3)
- Product: SonicWall SMA1000
- Affected: 12.4.3-03526 (platform-hotfix) and older versions, 12.5.0-02952 (platform-hotfix) and older versions
- Impact: CWE-441
- Status: Exploited in the wild
- EPSS: 0.5% (30-day)
- Action: See vendor advisory
CISA KEV isn't the only exploit signal for SonicWall CVEs. Pro/Team adds a second confirmed-exploit feed.
Try free for 14 daysWhy It Matters
Specifically, SonicWall assigned this flaw a maximum CVSS score of 10.0 in an official advisory. While the vendor initially reported no active attacks, threat hunters observed a different reality.
According to telemetry from Previdian, external attackers already send illicit traffic to exploit vulnerable systems. Thousands of enterprise gateways secure remote employee access worldwide based on industry telemetry estimates. Consequently, successful exploitation grants an intruder unauthorized control over internal network resources.
How the Attack Works
The security bug exists inside the WorkPlace portal of the remote access appliance. In particular, an unintended access path in the Extraweb interface handles incoming requests improperly. An outside attacker sends a crafted OPTIONS request that names the translation handler.
Furthermore, the request traverses the directory path into a design document rewrite function. This action forwards the unauthenticated traffic directly into an internal CouchDB database. As a result, the server-side request forgery bypasses normal perimeter authentication barriers.
Affected Versions
This severe SonicWall SMA1000 vulnerability affects physical models 6210 and 7210, alongside virtual 8200v gateways. Notably, platform branch 12.4.3 versions at or below 12.4.3-03526 remain exposed.
In addition, platform branch 12.5.0 builds at or below 12.5.0-02952 contain the same bug. Because September patch updates still contain the vulnerable code, older fixes provide no protection. However, SonicWall firewalls and the SMA 100 series do not share this security defect.
Patch and Mitigation Steps
Currently, the vendor offers no functional workarounds to prevent incoming exploitation attempts. Therefore, organizations must immediately apply the latest official hotfixes from the MySonicWall portal.
Administrators should upgrade branch 12.4.3 appliances to hotfix 12.4.3-03670 or later. Similarly, operators on branch 12.5.0 should upgrade to build 12.5.0-03082. Finally, remember that each appliance automatically reboots once hotfix installation finishes.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!