Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-10-08 · updated: 2026-10-08 · tags: [incident, global, ransomware] · confidence: high · severity: critical · affected_sectors: [global] · au_impact: false

SonicWall released hotfixes on 6 October for CVE-2026-102255, a 10.0-severity SSRF flaw in the Appliance WorkPlace interface of SMA1000 6210, 7210 and 8200v models. An unintended alternate access-path weakness lets a remote, unauthenticated attacker direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorised operations; the flaw does not affect the SMA 100 Series or SSL-VPN on SonicWall firewalls. SonicWall says there is currently no evidence any vulnerability in the release is being exploited in the wild, but Shadowserver tracks over 400 internet-exposed SMA1000 appliances — and the platform's history is why the advisory lands hard: this year alone, two SMA1000 zero-days (CVE-2026-15409/-15410) were exploited for weeks to install Sou5, OrangeTail and RootRun malware before CISA linked them to ransomware gangs in July, and two more (CVE-2026-83548/-83549) were chained for RCE in September. The SME1000/VPN-gateway estate is heavily used by government agencies, MSSPs and large corporates.

Attribute Detail
Sector Global (Macro)
Date 2026-10-08
Source BleepingComputer
Reliability Tier 1
CVEs CVE-2026-102255, CVE-2026-15409, CVE-2026-83548