Attack attempts target recently patched SonicWall remote-access devices
Source dates: SonicWall notice published 5 October and updated 6 October; attack attempts reported 9 October 2026
Activity observed: By 9 October 2026
A security researcher says a monitoring network has seen requests consistent with attempts to exploit CVE-2026-102255, a serious flaw in SonicWall SMA 1000 remote-access appliances. These devices help staff connect to an organisation’s internal systems. The researcher told BleepingComputer that the requests tried to make an appliance reach an internal database service. That is the idea behind *server-side request forgery*: an attacker persuades a trusted server to make a request on their behalf.
There is an important limit to the evidence. The researcher reported attempts, but could not establish that they had successfully compromised customer systems. SonicWall’s published notice still said it had no evidence of exploitation when the notice was updated. The new observation therefore warrants prompt checks without treating a confirmed breach as established.
SonicWall lists SMA 1000 models 6210, 7210 and 8200v running affected 12.4.3 or 12.5.0 firmware. Its fixed releases are 12.4.3-03670 and 12.5.0-03082, or later. The notice does not apply to every SonicWall firewall or to the separate SMA 100 series.
An organisation using these appliances should confirm its exact model and firmware, install the relevant hotfix and review access logs for unusual requests. A small business whose remote access is managed by an IT supplier can send that supplier the advisory and ask for confirmation that its gateway is updated.






Comments