Touchpoint Security Advisory

SonicWall SMA 1000 Pre-Auth Flaw, Exploited WordPress Form Plugins and the ASOS Customer Data Breach

TSTouchpoint Security·October 7, 2026

A maximum-severity, pre-authentication flaw in SonicWall's SMA 1000 remote access gateways leads today's brief. Attackers are also exploiting WordPress form and e-commerce plugins to plant hidden administrators, and Atlassian has patched a critical flaw in eight self-hosted products. ASOS has confirmed that customer names and contact details may have been accessed through a third-party messaging platform, another reminder that vendor access is a common route to customer data.

Priority at a glance

The Ninja Forms campaign is under confirmed active exploitation right now. SonicWall's flaw isn't yet reported exploited, but it's maximum severity on a product line already hit by two zero-days this year. Atlassian's bug is unexploited but critical. ASOS is a confirmed breach still under investigation.

Issue Exploited Fix status Our recommended timing
SonicWall SMA 1000, CVE-2026-102255 (pre-auth SSRF, max severity) No known exploitation yet 12.4.3-03670 or 12.5.0-03082+ Today, internet-facing units first
Ninja Forms + WPC Product Bundles (hidden-admin campaign) Yes, active campaign since Oct 4–5 Ninja Forms 3.15.5+, WPC Bundles 8.6.7 Today, both plugins, then check for hidden admins
Atlassian Data Center (8 products), CVE-2026-21589 (file read) No evidence reported; CVSS 4.0 9.3 Fixed releases available per product This week, internet-facing instances first
ASOS, customer data via third-party messaging platform N/A — vendor-access incident, under investigation Platform access restricted by ASOS Ongoing — review your own vendor messaging access

1. SonicWall patches maximum-severity pre-auth flaw in SMA 1000 gateways (CVE-2026-102255)

What happened. On October 7, SonicWall released fixes for a server-side request forgery (SSRF) flaw in the Workplace interface of its SMA 1000 remote access appliances, which it rates maximum severity. Without logging in, an attacker can make the appliance send requests on their behalf, reaching internal functions and performing unauthorized operations. The release also fixes three authenticated flaws (CVE-2026-102256, CVE-2026-102257 and CVE-2026-102258).

Who is affected. Models 6210, 7210 and 8200v, physical and virtual. Fixed firmware is 12.4.3-03670 or 12.5.0-03082 and later. SonicWall firewalls and the SMA 100 series are not affected.

Severity and context. SonicWall reports no exploitation so far. However, attackers exploited two earlier SMA 1000 zero-days (CVE-2026-83548 and CVE-2026-83549), which CISA added to its Known Exploited Vulnerabilities (KEV) catalog on September 2 — this product line has a recent track record of real-world attack.

What to do. — click a step to check it off

  1. Upgrade every SMA 1000 appliance now, internet-facing units first.
  2. Until then, restrict the Workplace and management interfaces to known address ranges.
  3. Review logs for unusual appliance requests to internal hosts. If earlier SMA 1000 patches were applied late, check appliance integrity and rotate credentials that pass through it.

2. Attackers exploit Ninja Forms and WooCommerce plugin flaws to plant hidden admins

What happened. Patchstack reported on October 6 an active campaign against two WordPress plugins: WPC Product Bundles for WooCommerce (CVE-2026-93836) from October 4, and Ninja Forms (CVE-2026-94504), used on more than 500,000 sites, from October 5. In Ninja Forms, an attacker submits a form containing a script. The script runs when an administrator opens the submission and uses that session to take over the site.

Who is affected. Ninja Forms 3.15.3 and earlier (CVSS 3.1 score 7.2, no login needed) and WPC Product Bundles 8.6.6 and earlier. A separate Ninja Forms flaw (CVE-2026-90438) is fixed in 3.15.5, so 3.15.5 or later is the right target, not 3.15.4. WPC Product Bundles is fixed in 8.6.7.

Severity and context. The attackers leave four ways back in: a visible rogue administrator, a hidden administrator, a secret login URL that signs in as the site owner, and a file manager inside a fake plugin named wp-smart-thumbnails.

What to do. — click a step to check it off, click any code snippet to copy it

  1. Update both plugins now.
  2. Check the mu-plugins folder, the wp-smart-thumbnails plugin, and the database options fz_emer_done_v1 and fz_emer_login_tokens. List administrators directly in the database, since one may be hidden from the dashboard.
  3. If you find signs of compromise, clean up, reset administrator passwords and WordPress salts, and assess whether stored form submissions were accessed — they often hold names, emails and phone numbers.

3. Atlassian fixes critical unauthenticated file-access flaw in eight Data Center products (CVE-2026-21589)

What happened. Atlassian disclosed this flaw on October 5 — we covered it in yesterday's brief — and the official CVE record now gives exact fixed versions for every affected product, below. The path traversal flaw lets an unauthenticated attacker read specific files in the web application root of self-hosted Data Center products, provided they know the exact file path. It does not allow directory listing.

Severity and context. CVSS 4.0 score 9.3. No exploitation is confirmed, but an earlier Confluence path traversal flaw (CVE-2021-26086) is on CISA's KEV list — this bug class has a history of real-world attack once a path traversal is found. Atlassian has already fixed its cloud products; Data Center customers must act.

Product (Data Center) Fixed versions
Jira Software 9.12.40, 10.3.26, 11.3.12
Jira Service Management 5.12.40, 10.3.26, 11.3.12
Confluence 9.2.26, 10.2.19
Bitbucket 9.4.26, 10.2.8, 10.5.1
Bamboo 10.2.24, 12.1.12
Crowd 6.3.7, 7.0.3, 7.1.7, 7.2.4
Crucible and Fisheye 4.9.15

What to do. — click a step to check it off

  1. Upgrade to the fixed version for your release line above, internet-facing instances first.
  2. If you cannot patch at once, restrict external access, or block ".." next to "/" or "\" in request paths at a WAF or reverse proxy, and review logs for such requests since October 5.

4. ASOS confirms customer data may have been accessed through a third-party messaging platform

What happened. On October 6, ASOS app users received unauthorized "ASOS HACKED" push notifications. ASOS said it was investigating unauthorized activity on third-party platforms it uses to communicate with customers and had restricted access to them. A group calling itself "Xuanye Group" claimed to have breached ASOS's Snowflake environment; Snowflake said it found no compromise of its own platform.

Who is affected. ASOS said names and contact details may have been accessed, but it does not believe payment card details or account passwords were. It has not said how many customers are involved.

What it means for customers. Names, emails and phone numbers are what fraudsters need for convincing phishing, such as fake refunds, delivery problems or security alerts. Customers should ignore links in unexpected messages and open the ASOS app or website directly instead; change their ASOS password if they've reused it elsewhere and turn on MFA where they can; and watch their bank and card statements, even though ASOS does not believe card data was involved.

What to do (organizations). — click a step to check it off

  1. Inventory every vendor that can message your customers or reach customer data.
  2. Confirm those vendor accounts use phishing-resistant MFA and are monitored for unusual exports or sends.

Compliance and personal data

No new US regulatory actions in the window HHS OCR and the FTC announced no new data security enforcement in the last 24 hours.
ASOS and the 72-hour clock Under UK GDPR, a qualifying breach must generally be reported to the Information Commissioner's Office within 72 hours of awareness, and affected people told without undue delay when the risk to them is high. EU GDPR may apply to customers outside the UK. Retailers in a similar position should document when they became aware, what the vendor platform held, and how they decided on notification.
Third-party access is today's common thread ASOS, Denmark's population register and the FBI were all exposed through vendor or partner access. GDPR Article 28, HIPAA business associate agreements and NIS2 all expect organizations to set, check and document vendor security: patch timelines in contracts, MFA on vendor accounts, and alerts on unusual lookups or exports.
A compromised WordPress site may be a data breach Victims of the Ninja Forms campaign should check whether stored submissions were readable. Whether notification is required depends on the data collected and where affected people live; many US state laws turn on items such as Social Security, driver's license or financial account numbers, or health data.

This section is general information, not legal advice.

Also notable

Denmark population register breach affects 8.8 million people Denmark announced on October 5 that unauthorized people misused a Danish company's legitimate access to the CPR register during September, obtaining names, addresses and CPR (national ID) numbers. People with name and address protection were not affected; the company's access was revoked and the case reported to the police and the data protection authority, Datatilsynet. Residents should be wary of calls or emails that quote their personal details and never share MitID codes or passwords.
FBI removes contractor after ShinyHunters breach Reuters reported on October 6 that the FBI removed an Accenture contractor after a missed security patch on a third-party-managed HR platform, identified by Reuters as Oracle PeopleSoft, let ShinyHunters steal personal details of thousands of FBI employees. Affected staff face elevated phishing and impersonation risk. Takeaway: patch obligations in vendor contracts need verification, not only assurances.
Federal deadline today for the latest NetScaler zero-day CISA added Citrix NetScaler CVE-2026-88779 to its KEV catalog on October 4 with a remediation due date of October 7 for federal civilian agencies. Other organizations running NetScaler should treat that date as their own.
Chrome 155 fixes 247 security flaws Google's October 7 stable release (155.0.8059.39/.40 for Windows and macOS, 155.0.8059.39 for Linux) includes four critical use-after-free fixes. Google has not reported exploitation; push the update through managed browser policies.
Nikkei discloses two employee account compromises The Japanese publisher said an employee Google Workspace account was compromised in late July, exposing names and email addresses of 1,646 people. A Microsoft 365 account was used to send about 9,000 phishing emails to staff and interviewees on September 30. Japan's personal information protection law is likely engaged; anyone who has corresponded with Nikkei should treat unexpected emails from its staff with caution.
Alleged Ploutus ATM malware developer in US court Anibal Alexander Canelon Aguirre, whom US officials link to the Tren de Aragua criminal group, pleaded not guilty in Nebraska on October 6 to charges including bank fraud conspiracy and material support to terrorists. The Ploutus malware is used to force ATMs to dispense cash.

Touchpoint's Take

Today's stories share one theme: attackers are abusing access that is trusted by design. A remote access gateway, an administrator's browser session, a vendor's messaging platform and a company's authorized access to a national register all fit that pattern, and misuse of each is easy to miss.

Behind today's numbers are shoppers, residents and employees who will now receive more convincing scams. Clear, prompt guidance for them is part of good incident response, not an afterthought.

What we would change in a security program:

  1. Patch edge appliances and self-hosted collaboration tools within days, especially product lines already exploited this year.
  2. Monitor vendor accounts and integrations for unusual volumes, not only failed logins. ASOS, Denmark's register and the FBI were all exposed through access that looked legitimate.
  3. Decide before an incident who owns notification decisions and how the 72-hour and state-law clocks are tracked.

If you would like help assessing your exposure to these issues or reviewing your third-party and breach-readiness controls, the Touchpoint Security team is available to talk.

Sources

  • Canadian Centre for Cyber Security: SonicWall security advisory AV26-872 (earlier SMA 1000 zero-days)
  • Help Net Security: SonicWall fixes pre-auth SSRF flaw in SMA 1000 appliances
  • BleepingComputer: SonicWall warns of max severity SSRF flaw in SMA1000 gateways
  • Patchstack: Four ways back in, the WordPress XSS campaign that hides its own admin account
  • CVE record: CVE-2026-94504
  • Patchstack database: Ninja Forms <= 3.15.4 unauthenticated stored XSS (CVE-2026-90438)
  • BleepingComputer: Ninja Forms plugin flaw exploited to hack WordPress sites
  • CVE record: CVE-2026-21589 (Atlassian CNA)
  • Atlassian: CONFSERVER-104488
  • Atlassian: JRASERVER-79546
  • The Hacker News: Critical Atlassian flaw lets unauthenticated attackers read known files across 8 products
  • BleepingComputer: Atlassian warns of critical file-access flaw in Jira, Confluence
  • SecurityWeek: ASOS confirms cyberattack, data breach
  • BleepingComputer: ASOS confirms data breach after "HACKED" in-app notifications
  • Danish government press release (ufm.dk): Extensive unauthorized access to citizens' CPR data
  • CISA Known Exploited Vulnerabilities catalog (data feed)
  • CISA: Adds one Known Exploited Vulnerability to catalog (October 4)
  • Nikkei notice 1547 and Nikkei notice 1554
  • HHS press room and FTC press releases
  • The Hacker News: FBI removes Accenture contractor after patch failure led to ShinyHunters breach
  • SecurityWeek: FBI blames contractor's missed patch for ShinyHunters breach
  • SecurityWeek: Chrome 155 update patches 247 vulnerabilities
  • BleepingComputer: Nikkei discloses breaches of employees' Microsoft, Google email accounts
  • The Record: Alleged ATM malware creator appears in Nebraska court after arrest
  • The Hacker News: Denmark says attackers accessed CPR data for 8.8 million people

Not sure where you stand on any of this?

Our team is available to talk through your exposure to today's issues.

Contact us