Skip to content
feed: live
0dayNews
CVE Record
[ CRITICAL ]CVE-2026-102255

Critical remote vulnerability in SonicWall SMA1000

Critical (CVSS 10.0) remote vulnerability in SonicWall SMA1000 appliances. Patched October 7, 2026. Active exploitation confirmed within 72 hours of patch release.

Vendor
SonicWall
Product
SMA1000
CVSS
10.0
EPSS (exploit probability)
0.5%
Status
exploited-in-wild
Published

CVE-2026-102255 is a maximum-severity (CVSS 10.0) vulnerability in SonicWall SMA1000 remote access appliances. SonicWall released a patch on October 7, 2026. Active exploitation in the wild was confirmed by October 9, roughly 72 hours later.

Affected administrators should apply the vendor patch immediately. Consult the NVD record and the SonicWall PSIRT portal for affected firmware versions and upgrade instructions.

SMA1000 has been a persistent target across 2026: two earlier zero-days in the same product line were exploited before patches shipped in September, and ransomware operators have repeatedly targeted unpatched SMA1000 units at the perimeter.