SonicWall's September SMA1000 fix is the newest build its 6 October advisory lists as affected
SonicWall's 1 September fix builds for two exploited SMA1000 flaws are the newest builds its 6 October advisory lists as affected by CVE-2026-102255, a 10.0 flaw with no known exploitation. Earlier 2026 SMA1000 flaws were already exploited when fixed, and this SSRF's reach gets one sentence.
By Parminder Kumar Sharma · · 18 min read

The 1 September fix build is the newest build on the 6 October affected list
SonicWall's advisory SNWLID-2026-0016, published on 1 September 2026, gave 12.4.3-03526 and 12.5.0-02952 as the platform hotfix builds that fix two SMA1000 flaws it said were being exploited. Its advisory SNWLID-2026-0017, published on 6 October, lists the builds affected by a new flaw, CVE-2026-102255, as 12.4.3-03526 and older and 12.5.0-02952 and older. The build SonicWall told customers to install 35 days earlier (derived) is now the newest build on the affected list. An appliance that did what the September advisory asked is still affected, and the builds that fix it are 12.4.3-03670 and 12.5.0-03082 or higher.
The same thing happened between July and September. The 14 July advisory, SNWLID-2026-0008, fixed in 12.4.3-03453 and 12.5.0-02835, and the September advisory lists exactly those two as its newest affected builds. Of the 221 advisories on SonicWall's PSIRT list when we read it, eight carry a CVSS of 10.0, and three of the eight are these SMA1000 advisories, published on 14 July, 1 September and 6 October, 84 days from first to last (derived). BleepingComputer reported the October advisory on 7 October and called the flaw a maximum-severity server-side request forgery (SSRF) in SMA1000 gateways. We read SonicWall's advisory, the CVE and NVD records and CISA's catalogue ourselves. Where BleepingComputer and those sources differ, this briefing follows the sources and says so.
What that does not establish. It does not say the new flaw is a way round the September fix. The advisory links the two nowhere. What we can check is that the component (the Appliance Work Place interface), the heading (pre-authentication SSRF via unintended forward-proxy), the pair of weakness classes and the score vector are the same in both advisories, and that is a similarity of shape, not a statement of cause. It does not say any appliance has been attacked through this flaw: SonicWall says it has no evidence of exploitation, on 6 October. It does not say where the affected range starts, because the advisory says "and older versions" with no floor. And a 10.0 is a score someone assigned, which the next section takes apart.
What "maximum severity" is a score of, and who gave it
BleepingComputer calls CVE-2026-102255 a maximum-severity flaw. The number is 10.0. It appears in three records but has two authors, SonicWall in its advisory and CISA-ADP in the entry that NVD repeats, and the CVE record that SonicWall itself filed does not contain it.
Where the 10.0 for CVE-2026-102255 appears and who wrote it. Sources: SonicWall PSIRT advisory, CVE Services API and NVD API, read on 7 October 2026.
- Record
- SonicWall advisory SNWLID-2026-0017 (the vendor)
- What it carries
- CVSS 10.0, vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H labelled as version 3.0; impact listed as critical on the PSIRT list
- What it leaves out
- How the score was reached, and how many appliances are reachable or attacked
- Record
- CVE record, SonicWall as the CNA
- What it carries
- The description, the affected builds, CWE-918 and CWE-441
- What it leaves out
- Any score: the CNA container has none
- Record
- CVE record, CISA-ADP container
- What it carries
- CVSS 3.1 base score 10.0 from the same eight metric values, and an SSVC reading of exploitation none, automatable yes, technical impact total, timestamped 7 October 15:50 UTC
- What it leaves out
- The basis for the SSVC reading, which is a coordinator's view of the public record at that moment
- Record
- NVD record
- What it carries
- Status Awaiting Analysis; the only score is the CISA-ADP 10.0, marked Secondary
- What it leaves out
- A score of NVD's own
| Record | What it carries | What it leaves out |
|---|---|---|
| SonicWall advisory SNWLID-2026-0017 (the vendor) | CVSS 10.0, vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H labelled as version 3.0; impact listed as critical on the PSIRT list | How the score was reached, and how many appliances are reachable or attacked |
| CVE record, SonicWall as the CNA | The description, the affected builds, CWE-918 and CWE-441 | Any score: the CNA container has none |
| CVE record, CISA-ADP container | CVSS 3.1 base score 10.0 from the same eight metric values, and an SSVC reading of exploitation none, automatable yes, technical impact total, timestamped 7 October 15:50 UTC | The basis for the SSVC reading, which is a coordinator's view of the public record at that moment |
| NVD record | Status Awaiting Analysis; the only score is the CISA-ADP 10.0, marked Secondary | A score of NVD's own |
The scores agree because they come from the same choices: network access, low complexity, no privileges, no user interaction, changed scope, and high impact on confidentiality, integrity and availability. We recomputed the CVSS 3.1 base score from those eight choices and got 10.0 (derived). A score of that kind says what an attacker could do if the description is right and the flaw is reachable. It does not say how reachable the interface is on your appliance, how many are exposed, or whether anyone is attacking. And scorers differ: for the stored cross-site scripting flaw in the same advisory, CVE-2026-102258, SonicWall's vector gives 5.5 and the CISA-ADP vector gives 6.1.
Method, not accusation. SonicWall wrote the advisory, assigned the CVE and chose the score, and it also sells the appliance and the fix. Volexity, whose July report is used below, sells incident response and wrote from its own client's case. Neither fact makes a statement wrong. Both mean the figures are theirs, and a reader should be able to see whose.
What the advisory says the flaw reaches, and what it leaves out
SSRF is a class of flaw in which a server is made to send a request it should not. What it means in practice depends on what the server can reach and what answers. SonicWall's only description of reach in its advisory is one sentence: a remote unauthenticated attacker "could potentially" direct the appliance to issue requests on their behalf and "reach internal functionality and perform unauthorized operations". Its heading for the flaw is "Pre-authentication SSRF via unintended forward-proxy", and the weakness list adds CWE-441, an unintended proxy or intermediary, which is also called a confused deputy.
What SonicWall's advisory of 6 October states and does not state about CVE-2026-102255. Source: SNWLID-2026-0017, read in full on 7 October 2026.
- Topic
- Where
- Stated
- The Appliance Work Place interface of SMA1000 models 6210, 7210 and 8200v. Not SMA 100, not SSL-VPN on SonicWall firewalls
- Not stated
- Whether a particular interface configuration is needed, or whether virtual and hardware units differ
- Topic
- Who
- Stated
- A remote unauthenticated attacker; network access, low complexity, no user interaction
- Not stated
- Any precondition beyond reaching the interface
- Topic
- Reach
- Stated
- Internal functionality and unauthorized operations, as a possibility
- Not stated
- Which functions or data, or whether code execution follows from this flaw alone
- Topic
- Affected
- Stated
- 12.4.3-03526 and older, 12.5.0-02952 and older
- Not stated
- The oldest affected build
- Topic
- Fixed
- Stated
- 12.4.3-03670 and higher, 12.5.0-03082 and higher; workaround: none
- Not stated
- Any interim control short of the hotfix
- Topic
- Exploitation
- Stated
- No evidence of any of the vulnerabilities being exploited in the wild
- Not stated
- What was checked, by whom, and for how long
- Topic
- Indicators
- Stated
- None: the Comments section of the advisory is empty
- Not stated
- Any log pattern, file or behaviour to look for
| Topic | Stated | Not stated |
|---|---|---|
| Where | The Appliance Work Place interface of SMA1000 models 6210, 7210 and 8200v. Not SMA 100, not SSL-VPN on SonicWall firewalls | Whether a particular interface configuration is needed, or whether virtual and hardware units differ |
| Who | A remote unauthenticated attacker; network access, low complexity, no user interaction | Any precondition beyond reaching the interface |
| Reach | Internal functionality and unauthorized operations, as a possibility | Which functions or data, or whether code execution follows from this flaw alone |
| Affected | 12.4.3-03526 and older, 12.5.0-02952 and older | The oldest affected build |
| Fixed | 12.4.3-03670 and higher, 12.5.0-03082 and higher; workaround: none | Any interim control short of the hotfix |
| Exploitation | No evidence of any of the vulnerabilities being exploited in the wild | What was checked, by whom, and for how long |
| Indicators | None: the Comments section of the advisory is empty | Any log pattern, file or behaviour to look for |
The advisory covers four CVEs, not one, and the other three are all post-authentication. SonicWall describes an operating system command injection scored 7.8 (CVE-2026-102256), a path traversal through archive extraction in the Appliance Management Console scored 7.2 (CVE-2026-102257), and stored cross-site scripting in the same console scored 5.5 (CVE-2026-102258). It says the first two can lead to code execution. For the command injection its text says a remote authenticated attacker acting as administrator, while its vector reads local access (AV:L) and low privileges (PR:L). The advisory does not reconcile the two.
The shape is not new. In both earlier pairs that SonicWall said were exploited, an unauthenticated SSRF sat beside an administrator-level command execution flaw in the same advisory, and CISA lists both halves of each pair. Volexity's analysis of the July pair, which we read, shows the two used as a chain, and its investigators found that the SSRF gave an unauthenticated route to services meant to be reachable only from the appliance itself. BleepingComputer says the September pair was also chained; we did not find a primary source for that. The October advisory does not say its flaws chain, and we have found no source that says they have been. The pairing is back, which is an inference about shape and not evidence of use.
Four SMA1000 advisories in 2026, and the two that reported exploitation were listed within a day
SonicWall's four SMA1000 advisories of 2026 against the CISA catalogue. Sources: SonicWall PSIRT advisories and CISA KEV version 2026.10.04, read on 7 October 2026. Days from advisory to listing are derived.
- Advisory and fix builds
- SNWLID-2026-0003, 8 April. Top score 7.2. Fixed in 12.4.3-03387 and 12.5.0-02624
- SonicWall's statement that day
- No evidence of exploitation
- CISA KEV (version 2026.10.04)
- None of its four CVEs listed
- Advisory and fix builds
- SNWLID-2026-0008, 14 July. CVE-2026-15409 (SSRF, 10.0) and CVE-2026-15410. Fixed in 12.4.3-03453 and 12.5.0-02835
- SonicWall's statement that day
- Multiple cases indicating active exploitation
- CISA KEV (version 2026.10.04)
- Both added 14 July, 0 days after; ransomware use Known; due 17 July
- Advisory and fix builds
- SNWLID-2026-0016, 1 September. CVE-2026-83548 (SSRF, 10.0) and CVE-2026-83549. Fixed in 12.4.3-03526 and 12.5.0-02952
- SonicWall's statement that day
- A case indicating active exploitation
- CISA KEV (version 2026.10.04)
- Both added 2 September, 1 day after; ransomware use Unknown; due 5 September
- Advisory and fix builds
- SNWLID-2026-0017, 6 October. CVE-2026-102255 (SSRF, 10.0) and three more. Fixed in 12.4.3-03670 and 12.5.0-03082
- SonicWall's statement that day
- No evidence of exploitation
- CISA KEV (version 2026.10.04)
- Not listed; the version is dated 4 October, two days before the advisory
| Advisory and fix builds | SonicWall's statement that day | CISA KEV (version 2026.10.04) |
|---|---|---|
| SNWLID-2026-0003, 8 April. Top score 7.2. Fixed in 12.4.3-03387 and 12.5.0-02624 | No evidence of exploitation | None of its four CVEs listed |
| SNWLID-2026-0008, 14 July. CVE-2026-15409 (SSRF, 10.0) and CVE-2026-15410. Fixed in 12.4.3-03453 and 12.5.0-02835 | Multiple cases indicating active exploitation | Both added 14 July, 0 days after; ransomware use Known; due 17 July |
| SNWLID-2026-0016, 1 September. CVE-2026-83548 (SSRF, 10.0) and CVE-2026-83549. Fixed in 12.4.3-03526 and 12.5.0-02952 | A case indicating active exploitation | Both added 2 September, 1 day after; ransomware use Unknown; due 5 September |
| SNWLID-2026-0017, 6 October. CVE-2026-102255 (SSRF, 10.0) and three more. Fixed in 12.4.3-03670 and 12.5.0-03082 | No evidence of exploitation | Not listed; the version is dated 4 October, two days before the advisory |
The April advisory's fix builds, 12.4.3-03387 and 12.5.0-02624, are among the builds the July advisory lists as affected, although 12.4.3-03434 and 12.5.0-02800 are the newest affected builds it names. So the match between one advisory's fix and the next advisory's newest affected build holds for two of the three consecutive pairs, July to September and September to October.
Intervals, all derived: 14 July to 1 September is 49 days, 1 September to 6 October is 35, and 14 July to 6 October is 84. Volexity, which helped SonicWall's July investigation, says the earliest sign of compromise it saw was on 22 June, 22 days before the advisory. All four 2026 SMA1000 entries in the catalogue carry CISA's forensic triage flag set to Yes, which none of the 15 older SonicWall entries do.
BleepingComputer's catalogue figures check out. It says CISA has added 19 SonicWall vulnerabilities to its exploited list over four years and that 13 have been abused in ransomware attacks. From the catalogue JSON itself we count 19 entries with SonicWall as the vendor and 13 with known ransomware campaign use, so the figures agree. Two details differ. The earliest SonicWall entry is dated 3 November 2021, which makes the span 4 years and 11 months, not four years (derived). And six of the 19 are SMA1000 entries, all added since 24 January 2025, four of them this year (derived). Its account of the July pair also holds: both are listed as known ransomware campaign use. For the September pair the catalogue says Unknown, and BleepingComputer does not claim otherwise.
Two earlier briefings on this site cover the catalogue side. Cisco gave customers a compromise hunting command 47 days before the same advisory said the flaw was exploited tabulates five management plane flaws that reached the catalogue, including the September SonicWall pair, each with a three day federal deadline. CISA added 34 flaws to the exploited catalogue in September, and 26 came with a three day deadline explains why that deadline is now the usual one.
"No evidence of exploitation" is a statement with a date
SonicWall's sentence, dated 6 October, says there is currently no evidence that any of the vulnerabilities in this release are being exploited in the wild. It states a position on one day. It does not say how SonicWall looked, or what it can see on appliances it does not manage. Four things in the record limit what that sentence can carry.
The 2026 pattern is attack first, fix second. In July the advisory itself reported multiple cases of active exploitation and Volexity put the earliest compromise 22 days before it. In September the advisory reported a case. For those two there was no interval from fix to attack to measure, because the fix was the first public notice of attacks already under way. If October differs, it differs in how the flaw came to light: the advisory credits a researcher at Anthropic for CVE-2026-102255 and CVE-2026-102256, while the July and September advisories credit SonicWall's own staff, with Volexity named in July for helping the investigation. A flaw reported from outside was found by a researcher, which says nothing about whether anyone hostile found it as well.
A fix is also a description of the flaw. The NCSC's update guidance says that once a vulnerability is fixed, attackers will often study it and try to write exploits, which sets up a race between those updating and those attacking. The CISA coordinator's reading in the CVE record is automatable yes and technical impact total, with exploitation none at 15:50 UTC on 7 October. How long the race takes here is not something any source states.
The catalogue's silence carries no information yet. The latest CISA catalogue we could read, version 2026.10.04, was released on 4 October, two days before the advisory, so its not listing CVE-2026-102255 cannot be read as a finding. The NCSC's active exploitation guidance also notes that the catalogue reports only exploitation that has already happened.
The exposure figure counts devices, not vulnerable devices. BleepingComputer says Shadowserver tracks over 400 internet-exposed SMA1000 appliances, although some may have been patched. On Shadowserver's dashboard the series for devices identified as SonicWall SMA 1000 totals 412 on 6 October, the latest day, and ranges from 407 to 511 over the seven days from 30 September (derived by summing the six continent series). Of the 412, 140 were in Europe and 23 in the United Kingdom. Shadowserver describes the underlying device identification report as a device population report in which "no assessment is made on the vulnerability state of the device". A device that answers like an SMA1000 may or may not be patched, and the series we read carries no build numbers.
There is a longer tail to this kind of gateway. An earlier briefing on Microsoft's weaponisation figure records that a different SonicWall VPN flaw, CVE-2024-40766, was added to the catalogue on 9 September 2024, a year before the ransomware surge Microsoft's report describes. We checked that date in the catalogue.
What this means for UK organisations
Who runs these. BleepingComputer says SMA1000 gateways are used by government agencies, managed service providers and many large corporations to give VPN access to internal applications. It does not say in which countries. Shadowserver's dashboard identifies 23 SMA 1000 devices in the United Kingdom on 6 October, within a range of 13 to 23 across the week. That is a count of devices, not of organisations or of vulnerable units. A managed service provider may run one for many customers, and a customer may not know which build it is on. We found no NCSC publication naming SonicWall or this CVE in the NCSC's RSS feed (its 20 most recent items, read on 7 October), which says nothing about what the NCSC may have said elsewhere.
The patching clocks that apply to a hotfix released on 6 October 2026. Sources: Cyber Essentials Requirements for IT Infrastructure v3.3 (April 2026), NCSC vulnerability management guidance version 2.1. Dates are derived.
- Rule
- Cyber Essentials v3.3, Security Update Management
- What it requires
- Updates within 14 days of release where the vendor calls the vulnerabilities critical or high risk, or the CVSS v3 score is 7 or above; one critical or high fix in a bundle brings the whole update inside 14 days
- Date for a 6 October hotfix
- 20 October 2026
- Rule
- NCSC, update by default
- What it requires
- Internet-facing services and software: install on a test environment or backup first, then test and roll out, completed within 5 days
- Date for a 6 October hotfix
- 11 October 2026, a Sunday
- Rule
- NCSC, responding to active exploitation
- What it requires
- Compressed timelines of under 24, 48 or 72 hours plus a cyber incident response investigation, set out for flaws on the CISA catalogue
- Date for a 6 October hotfix
- Does not apply as written: CVE-2026-102255 is not on the version read
| Rule | What it requires | Date for a 6 October hotfix |
|---|---|---|
| Cyber Essentials v3.3, Security Update Management | Updates within 14 days of release where the vendor calls the vulnerabilities critical or high risk, or the CVSS v3 score is 7 or above; one critical or high fix in a bundle brings the whole update inside 14 days | 20 October 2026 |
| NCSC, update by default | Internet-facing services and software: install on a test environment or backup first, then test and roll out, completed within 5 days | 11 October 2026, a Sunday |
| NCSC, responding to active exploitation | Compressed timelines of under 24, 48 or 72 hours plus a cyber incident response investigation, set out for flaws on the CISA catalogue | Does not apply as written: CVE-2026-102255 is not on the version read |
Whether a given SMA1000 is in scope of a Cyber Essentials assessment is a decision for the organisation and its certification body, and we have not assumed it is. If it is, SonicWall's own description (impact critical, score 10.0) puts the hotfix inside the 14 day rule, and the NCSC's timescale for internet-facing software is shorter than the scheme's. Cyber Essentials also asks that the administrative interface of a firewall, or of a network device with firewall functionality, is not reachable from the internet unless there is a documented business need and it is protected by multi-factor authentication or a short allow list. SonicWall places two of the four CVEs in the Appliance Management Console. The SSRF is in the Work Place interface, which users reach by design, and SonicWall lists no workaround, so limiting the console does not remove the exposure that matters most here.
The NCSC's alert of 27 August on internet-exposed systems and edge devices asks organisations outside operational technology for the basics this advisory tests: an accurate inventory of internet-facing systems, an understanding of each edge device's function and data flows, prompt vendor updates, and monitoring for unexpected configuration changes or outbound connections. It also asks every organisation to register for the free Early Warning service. Early Warning reports vulnerabilities and open ports from information feeds and does not scan your network itself, and we have not seen that it covers this CVE. On suppliers, the NCSC's active exploitation guidance says critical suppliers and managed service providers should be contractually liable to mitigate exploited vulnerabilities in internet-accessible systems quickly. For this CVE nobody yet says exploitation, so that trigger may not have fired. Ask anyway.
What to do, in order
Take this with you
Defender actions, in the order worth doing
- List every SMA1000 you run or that a supplier runs for you: hardware 6210 and 7210, virtual 8200v, disaster recovery and test units. Record the exact build string of each and who is responsible for patching it.
- Compare each build with the advisory. Affected is 12.4.3-03526 and older and 12.5.0-02952 and older. Fixed is 12.4.3-03670 or higher and 12.5.0-03082 or higher. An appliance on the 1 September fix build is affected.
- Before patching, follow SonicWall's own hotfix article: export a configuration backup, snapshot a virtual appliance from its host, check the download against the published checksum, expect a reboot that drops connected users, and have console access ready. That article is dated 2020, so also read the technote that comes with the hotfix.
- Apply the platform hotfix for your firmware line. SonicWall's article says hotfixes are cumulative and that a hotfix for one firmware cannot be applied to another. Aim for the NCSC's five days, 11 October, and treat Cyber Essentials' 14 days, 20 October, as the limit.
- While you wait for the change window, restrict the Appliance Management Console to a management network or a short allow list, as the NCSC and Cyber Essentials advise. This does not mitigate the new SSRF flaw, which is in the interface users reach, and SonicWall lists no workaround.
- Review the appliance's logs and its outbound connections for the period you ran affected builds. This advisory publishes no indicators, so look for the appliance connecting to internal addresses or services it does not normally use, and for unexpected configuration changes, as the NCSC edge device alert advises.
- Confirm that someone did the compromise review SonicWall asked for in July, where the advisory and Volexity's report list indicators, and in September, where SonicWall asked customers to contact its support. SonicWall's own advice for a positive finding is to re-image or redeploy, change all user and administrator passwords and reset TOTP tokens, which tells you a hotfix alone is not treated as remediation.
- Ask your managed service provider in writing which SMA1000 builds it runs for you, when each was patched and who watches for the next advisory.
- Re-read the CISA catalogue for CVE-2026-102255 before you close the change. If it appears, the NCSC's compressed timelines apply and CISA's entries for this product have carried a forensic triage requirement since July.
- Register the addresses of the appliances with the NCSC's free Early Warning service if you have not already.
What is not established, and what I could not read
- Whether any appliance has been attacked through CVE-2026-102255. SonicWall said no evidence on 6 October, and no source we read says otherwise.
- What internal functionality the flaw reaches. The advisory gives one sentence.
- Whether the flaw is related to September's. Only the shape matches.
- The hotfix release time and download checksums. The mysonicwall.com download page needs an account and was not opened, so a release on Tuesday 6 October rests on the advisory date and BleepingComputer.
- How many appliances are affected, as against merely identifiable. Shadowserver counts devices and shows no build.
- NVD's own analysis and score. The record was awaiting analysis.
- Whether CISA will list the flaw. The catalogue version read predates the advisory.
The question
SonicWall has now put out three SMA1000 advisories with 10.0 flaws in 84 days, and in the second and third the previous fix build was the newest build on the affected list. "Patched in September" is a friendly label. A hotfix is a name and an advisory is a date, and the only control is the build string on each gateway.
So which build is each of your SMA1000 gateways running at this minute, and who in your organisation, or at your managed service provider, compares the next advisory with it?
Key facts
Sources
- PrimaryAdvisory SNWLID-2026-0017, first published 6 October 2026, read in full in a browser at about 17:47 BST on 7 October 2026. The primary source: four CVEs, affected and fixed builds, scores, the no-evidence statement, the empty Comments section, credits. SonicWall wrote the score and sells the product.SonicWall PSIRTaccessed 2026-10-07
- PrimaryAdvisory SNWLID-2026-0016, first published 1 September 2026, read in full: the 12.4.3-03526 and 12.5.0-02952 fix builds, the exploitation statement, the recommended actions.SonicWall PSIRTaccessed 2026-10-07
- PrimaryAdvisory SNWLID-2026-0008, first published 14 July 2026, read in full: the 12.4.3-03453 and 12.5.0-02835 fix builds, the exploitation statement, the indicator and recommended action sections, credits.SonicWall PSIRTaccessed 2026-10-07
- PrimaryAdvisory SNWLID-2026-0003, first published 8 April 2026, read in full: 12.4.3-03387 and 12.5.0-02624 fix builds and the no-evidence statement.SonicWall PSIRTaccessed 2026-10-07
- PrimaryThe PSIRT vulnerability list, read through the page's own public API at about 17:48 BST on 7 October 2026: 221 advisories, publication timestamps, the eight advisories carrying a CVSS of 10.0 and the four SMA1000 advisories of 2026.SonicWall PSIRTaccessed 2026-10-07
- PrimaryCVE record for CVE-2026-102255 read through the CVE Services API: SonicWall as CNA with no score, reserved 28 September, declared public 7 October 13:01 UTC and published 13:07 UTC, and the CISA-ADP container with the 3.1 vector, score 10.0 and the SSVC reading.CVE Programaccessed 2026-10-07
- PrimaryCVE record for CVE-2026-102258, read with the records for CVE-2026-102256 and CVE-2026-102257: the CISA-ADP scores 6.1, 7.8 and 7.2 set beside SonicWall's 5.5, 7.8 and 7.2.CVE Programaccessed 2026-10-07
- PrimaryNVD record for CVE-2026-102255 read at 17:46 BST on 7 October 2026: status Awaiting Analysis, the CISA-ADP 3.1 score marked Secondary and no score of NVD's own.NIST NVDaccessed 2026-10-07
- PrimaryKnown Exploited Vulnerabilities catalogue, version 2026.10.04, released 4 October 2026 at 18:52 UTC, 1,734 entries, fetched at 17:46 BST on 7 October 2026. Source of the SonicWall counts, the dates added, the ransomware flags, the due dates and the forensic triage field.CISAaccessed 2026-10-07
- PrimaryProxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation, 17 July 2026, read in full. Used for the earliest sign of compromise on 22 June and the post-exploitation findings, at defender level only. Volexity sells incident response and wrote from its own client's case.Volexityaccessed 2026-10-07
- PrimaryDashboard time series of devices identified as SonicWall SMA 1000, 30 September to 6 October 2026, read through the dashboard's own embedded chart data, grouped by continent and filtered to the United Kingdom.The Shadowserver Foundationaccessed 2026-10-07
- PrimaryDevice Identification Report description: a device population report with no assessment of vulnerability state, based on publicly accessible responses.The Shadowserver Foundationaccessed 2026-10-07
- PrimaryKnowledge base article How to apply or rollback Hotfix on SMA1000 Device, marked updated 22 October 2020 and read on 7 October 2026: configuration backup, snapshot, checksum, reboot, cumulative hotfixes, firmware line.SonicWallaccessed 2026-10-07
- PrimaryCyber Essentials: Requirements for IT Infrastructure v3.3, April 2026, read in full with pypdf: the Security Update Management requirement (14 days) and the firewall administrative interface requirement.NCSCaccessed 2026-10-07
- PrimaryVulnerability management, 1. Put in place a policy to update by default, version 2.1, reviewed 1 May 2026: the five day timescale for internet-facing software, install on a test environment or backup first, the race after a fix, and check for compromise before updating when exploited.NCSCaccessed 2026-10-07
- PrimaryVulnerability management, 2. Responding to active exploitation of vulnerabilities, version 2.1, reviewed 1 May 2026: the compressed timelines table, the limits of the CISA catalogue and supplier contract wording.NCSCaccessed 2026-10-07
- PrimaryDisruptive cyber activity highlights risk from internet-exposed systems and edge devices, published 27 August 2026: advice for organisations outside operational technology and the Early Warning recommendation.NCSCaccessed 2026-10-07
- PrimaryEarly Warning service page: free alerts including vulnerability and open port alerts, built from information feeds without active scanning by the NCSC.NCSCaccessed 2026-10-07
- PrimaryProtect your management interfaces, a blog post published 22 March 2017: expose management interfaces to dedicated management networks or at least limit inbound addresses. Older guidance, cited for the principle.NCSCaccessed 2026-10-07
- PrimaryThe NCSC's site-wide RSS feed, 20 most recent items, read on 7 October 2026 to check for any item naming SonicWall: none found.NCSCaccessed 2026-10-07
- Reported bySonicWall warns of max severity SSRF flaw in SMA1000 gateways, 7 October 2026, the news pointer, read in a browser in my own tab. Used for the Shadowserver figure, the 19 and 13 KEV counts, the users of SMA1000 and the earlier CVEs, each of which was checked against a primary.BleepingComputeraccessed 2026-10-07
- Reported bySonicWall SMA1000 flaws exploited as zero-days to push custom malware, 20 July 2026, read to check the 'exploited for weeks' claim and to find Volexity's report. The September chaining claim comes from a further BleepingComputer article that was not read.BleepingComputeraccessed 2026-10-07


