HomeBig TechSonicWall Attack Attempts, a $1.26m Pwn2Own and a Windows Update Deadline

SonicWall Attack Attempts, a $1.26m Pwn2Own and a Windows Update Deadline

Three security items from 8 and 9 October 2026: a maximum-severity SonicWall flaw that attackers are reportedly probing, the Pwn2Own Ireland results, and a Microsoft deadline that will cut some Windows PCs off from updates in 2027. TSN gives no exploit details.

Spotted via Previdian (@PrevidianCyber) on X, BleepingComputer (@BleepinComputer) on X, TrendAI Zero Day Initiative (@thezdi) on X and BleepingComputer on X (Pwn2Own, Windows).

SonicWall SMA1000: patched, with attack attempts reported

Patch confirmed; successful exploitation unconfirmed. SonicWall has fixed CVE-2026-102255, a flaw in the WorkPlace interface of its SMA1000 remote-access appliances. The US National Vulnerability Database (NVD) record, published on 7 October and citing SonicWall’s advisory SNWLID-2026-0017, scores it 10.0 out of 10 [1][2]. It describes a pre-authentication flaw that could let “a remote unauthenticated attacker” make the appliance “issue requests on their behalf and reach internal functionality and perform unauthorized operations” [1]. BleepingComputer says it affects the SMA1000 6210, 7210 and 8200v, not the SMA 100 series or SonicWall firewalls [3].

On 9 October the security firm Previdian posted that “exploitation attempts are now being observed by Previdian sensors, consistent with CVE-2026-102255” (reported, company post) [4]. Its founder, Ryan Dewhurst, told BleepingComputer the firm has not established “whether those attempts would have successfully compromised any systems” [3]. SonicWall had not flagged the flaw as exploited, according to BleepingComputer, and it was not in CISA’s Known Exploited Vulnerabilities (KEV) catalogue when TSN checked [3][5]. BleepingComputer’s headline (“now exploited in attacks”) goes further than its own reporting of attempts [3].

Shadowserver tracks “more than 400” exposed SMA1000 appliances, per BleepingComputer [3]. Other SMA1000 flaws were exploited earlier this year and are on the KEV list [5].

Pwn2Own Ireland: $1,262,000 for 98 zero-days

Day-three awards confirmed (ZDI); totals reported (BleepingComputer). At Pwn2Own, run by the Zero Day Initiative (ZDI), researchers demonstrate previously unknown flaws (“zero-days”) for cash; the bugs go to vendors to fix.

BleepingComputer reports that the three-day event ended with “$1,262,000 in rewards after exploiting 98 zero-day flaws” [6]. Ikotas Labs won the “Master of Pwn” title with “42.5 Master of Pwn points and $361,000”, it says [6]. ZDI’s day-three results credit Ikotas with $300,000 for an exploit chain against the Google Pixel 10, the largest award of the final day [7]. Xint won $150,000 for a Pixel 10 attempt using an already-reported bug, and a CENSUS Labs and Mobile Hacking Lab team won $112,500 [7].

Targets included phones, AI infrastructure, AI coding apps, smart-home devices and printers [6]. Vendors have 90 days to patch before ZDI publishes details [6].

Windows Update certificates expire in 2027

Confirmed (Microsoft). Microsoft says “Certificates used to establish trusted connections to Windows Update will expire on May 17, 2027 and June 19, 2027”, and “Devices without the replacement certificates will lose access to Windows Update after the applicable expiration date” [8]. Most in-support PCs that are current with monthly updates need do nothing [8]:

  • Windows 11 version 25H2 and later: no action.
  • Windows 11 version 24H2 and Windows Server 2025: install the September 2025 security update or later before 19 June 2027.
  • Other in-support Windows 11, Windows Server 2022 and in-support Windows 10: install the July 2026 security update or later before 19 June 2027.
  • Windows 10 Enterprise 2019 LTSC, Windows Server 2019 and Windows Server 2016: install the July 2026 security update or later before 17 May 2027.
  • Other versions: upgrade to a supported version.

Devices that get updates through Windows Server Update Services (WSUS) are not affected [8][9].

What this does not prove

  • That any SMA1000 has been breached through CVE-2026-102255. Previdian reports attempts “consistent with” the flaw; success is unconfirmed, and SonicWall had not flagged exploitation [3][4].
  • That Pwn2Own bugs are used by criminals. They were contest demonstrations disclosed to vendors [6][7].
  • That up-to-date, supported Windows PCs will stop updating. Microsoft says most need no action [8].

The Bottom Line

SonicWall SMA1000 owners should patch now: attack attempts are reported, though no compromise is confirmed. Pwn2Own Ireland paid $1,262,000 for 98 zero-days that vendors must now fix. And Windows machines on old or unsupported versions need updating or upgrading before May or June 2027.

Related on TSN: Cyber breaches this week: credential reuse, retail alerts, campus ransomware and edge-gear risk

Sources

  1. NIST National Vulnerability Database, CVE-2026-102255, published 7 October 2026, 14:17 BST (status “Awaiting Analysis”; CVSS 3.1 score 10.0 supplied by SonicWall as the CVE numbering authority; read via the NVD API). https://nvd.nist.gov/vuln/detail/CVE-2026-102255
  2. SonicWall PSIRT, advisory SNWLID-2026-0017 (vendor advisory; the page is a JavaScript app that TSN’s tools could not render, so its wording is taken from the NVD record that cites it). https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0017
  3. Sergiu Gatlan, “Max severity SonicWall SMA1000 flaw now exploited in attacks”, BleepingComputer, 9 October 2026, 13:32 BST (trade press; source of the Dewhurst quote, model list and Shadowserver count; the headline goes further than the article body). https://www.bleepingcomputer.com/news/security/max-severity-sonicwall-sma1000-flaw-now-exploited-in-attacks/
  4. Previdian (@PrevidianCyber), X post, 9 October 2026, 09:55 BST (company post, read via the X API). It goes beyond the primary evidence by publishing an attacker IP address, which TSN does not reproduce. https://x.com/PrevidianCyber/status/2108481433010340097
  5. CISA, Known Exploited Vulnerabilities catalogue (JSON feed, catalogue version 2026.10.08), checked 9 October 2026, 14:20 BST: CVE-2026-102255 not listed; SMA1000 flaws CVE-2026-83548 and CVE-2026-83549 added 2 September 2026. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  6. Sergiu Gatlan, “Hackers get $1,262,000 for 98 zero-days at Pwn2Own Ireland”, BleepingComputer, 9 October 2026, 06:41 BST (trade press; source of the contest totals). https://www.bleepingcomputer.com/news/security/hackers-earn-1262000-for-98-zero-days-at-pwn2own-ireland/
  7. Zero Day Initiative, “Pwn2Own Ireland 2026 – Day Three Results & Master of Pwn”, 8 October 2026 (organiser). https://www.zerodayinitiative.com/blog/2026/10/8/pwn2own-ireland-2026-day-three-results-amp-master-of-pwn
  8. Microsoft, Windows message center, “Prepare for Windows Update certificate rotation in 2027”, 8 October 2026, 12:00 PT (20:00 BST) (official), with the linked Windows IT Pro blog post. https://learn.microsoft.com/en-us/windows/release-health/windows-message-center and https://techcommunity.microsoft.com/blog/windows-itpro-blog/prepare-for-windows-update-certificate-rotation-in-2027/4562463
  9. Sergiu Gatlan, “Microsoft: Outdated Windows devices will lose security protection next year”, BleepingComputer, 9 October 2026, 11:12 BST (trade press). https://www.bleepingcomputer.com/news/microsoft/microsoft-outdated-windows-devices-will-lose-security-protection-next-year/
  10. BleepingComputer (@BleepinComputer), X post, 9 October 2026, 13:33 BST (read via the X API). Its wording, “now exploited in attacks”, goes beyond the evidence in the article, which reports attempts only. https://x.com/BleepinComputer/status/2108536264156750257
  11. TrendAI Zero Day Initiative (@thezdi), X post, 8 October 2026, 21:10 BST (organiser; read via the X API; matches the day-three blog). https://x.com/thezdi/status/2108288983360766188
  12. BleepingComputer (@BleepinComputer), X posts, 9 October 2026, 06:41 BST (Pwn2Own) and 11:15 BST (Windows; read via the X API). The Windows post frames the change as unsupported devices losing updates “starting in May 2027”; Microsoft’s notice gives two dates and also covers supported devices that miss the listed updates. https://x.com/BleepinComputer/status/2108432611521470895 and https://x.com/BleepinComputer/status/2108501533008474260

Share this story

More in this category

Latest on TSN

Free TSN tools: crypto calculator, Flux dashboard and more.