Tidavo
Thursday 8 October 2026

SonicWall releases urgent security updates for corporate remote access appliances

A critical software flaw allowed remote outsiders to reach internal network functions without logging in.

8 Oct 2026

SonicWall has issued urgent software repairs for its SMA 1000 remote access devices. The update addresses four security weaknesses discovered in the equipment, which companies and government bodies rely on to connect remote staff securely to office systems.

The most dangerous flaw is CVE-2026-102255, which received a maximum severity rating of 10.0. It is a server-side request forgery flaw, a type of bug where a system can be fooled into passing unauthorized network messages deeper into a private setup.

This primary weakness sits in the appliance WorkPlace login page. Because of an unintended backup route in the code, an outsider does not need a username or password to trigger it. The attacker can force the gateway to issue requests on their behalf, gaining access to private endpoints that automatically trust the appliance.

Three other vulnerabilities were corrected alongside the critical bug. However, these require someone to already be logged in as an administrator. One allows command injection directly into the underlying operating system, another is an archive extraction bug that lets users slip files into restricted folders, and the third allows malicious website scripts to be stored on the management console.

Outside researchers found and reported the problems. Benoît Sevens discovered both the critical portal flaw and the command injection bug. Brian Mariani reported the archive extraction issue and the script storage weakness.

The updates apply to physical and virtual SMA 1000 models, specifically the 6210, 7210, and 8200v units. Reports vary on the exact build numbers, with one citing versions 12.4.3-03526 and 12.5.0-02952 or older as vulnerable, while another notes administrators should install versions 12.4.3-03670 and 12.5.0-03082 or newer. Standard SonicWall firewalls and the separate SMA 100 product line are not affected.

SonicWall stated that there is no temporary workaround for the main defect, meaning administrators must install the official update files through the customer portal. The company reported no evidence that hackers have actively targeted this specific batch of bugs so far.

Security teams remain on high alert because the SMA 1000 line has faced repeated break-ins this year. Attackers exploited two similar gateway flaws in July to plant custom malware, which federal authorities linked to ransomware groups. Another pair of flaws was chained together in early September to run code on target devices.

Threat tracking group Shadowserver found more than 400 of these gateways openly exposed to the internet. Because these appliances protect vital networks for large corporations, service providers, and public agencies, leaving the devices unpatched creates an easy doorway into private company data.

Security Affairs , BleepingComputer , Help Net Security