SonicWall SMA 1000 Pre-Auth Flaw, Exploited WordPress Form Plugins and the ASOS Customer Data Breach
A maximum-severity, pre-authentication flaw in SonicWall's SMA 1000 remote access gateways leads today's brief. Attackers are also exploiting WordPress form and e-commerce plugins to plant hidden administrators, and Atlassian has patched a critical flaw in eight self-hosted products. ASOS has confirmed that customer names and contact details may have been accessed through a third-party messaging platform, another reminder that vendor access is a common route to customer data.
Priority at a glance
The Ninja Forms campaign is under confirmed active exploitation right now. SonicWall's flaw isn't yet reported exploited, but it's maximum severity on a product line already hit by two zero-days this year. Atlassian's bug is unexploited but critical. ASOS is a confirmed breach still under investigation.
| Issue | Exploited | Fix status | Our recommended timing |
|---|---|---|---|
| SonicWall SMA 1000, CVE-2026-102255 (pre-auth SSRF, max severity) | No known exploitation yet | 12.4.3-03670 or 12.5.0-03082+ | Today, internet-facing units first |
| Ninja Forms + WPC Product Bundles (hidden-admin campaign) | Yes, active campaign since Oct 4–5 | Ninja Forms 3.15.5+, WPC Bundles 8.6.7 | Today, both plugins, then check for hidden admins |
| Atlassian Data Center (8 products), CVE-2026-21589 (file read) | No evidence reported; CVSS 4.0 9.3 | Fixed releases available per product | This week, internet-facing instances first |
| ASOS, customer data via third-party messaging platform | N/A — vendor-access incident, under investigation | Platform access restricted by ASOS | Ongoing — review your own vendor messaging access |
1. SonicWall patches maximum-severity pre-auth flaw in SMA 1000 gateways (CVE-2026-102255)
What happened. On October 7, SonicWall released fixes for a server-side request forgery (SSRF) flaw in the Workplace interface of its SMA 1000 remote access appliances, which it rates maximum severity. Without logging in, an attacker can make the appliance send requests on their behalf, reaching internal functions and performing unauthorized operations. The release also fixes three authenticated flaws (CVE-2026-102256, CVE-2026-102257 and CVE-2026-102258).
Who is affected. Models 6210, 7210 and 8200v, physical and virtual. Fixed firmware is 12.4.3-03670 or 12.5.0-03082 and later. SonicWall firewalls and the SMA 100 series are not affected.
Severity and context. SonicWall reports no exploitation so far. However, attackers exploited two earlier SMA 1000 zero-days (CVE-2026-83548 and CVE-2026-83549), which CISA added to its Known Exploited Vulnerabilities (KEV) catalog on September 2 — this product line has a recent track record of real-world attack.
What to do. — click a step to check it off
- Upgrade every SMA 1000 appliance now, internet-facing units first.
- Until then, restrict the Workplace and management interfaces to known address ranges.
- Review logs for unusual appliance requests to internal hosts. If earlier SMA 1000 patches were applied late, check appliance integrity and rotate credentials that pass through it.
2. Attackers exploit Ninja Forms and WooCommerce plugin flaws to plant hidden admins
What happened. Patchstack reported on October 6 an active campaign against two WordPress plugins: WPC Product Bundles for WooCommerce (CVE-2026-93836) from October 4, and Ninja Forms (CVE-2026-94504), used on more than 500,000 sites, from October 5. In Ninja Forms, an attacker submits a form containing a script. The script runs when an administrator opens the submission and uses that session to take over the site.
Who is affected. Ninja Forms 3.15.3 and earlier (CVSS 3.1 score 7.2, no login needed) and WPC Product Bundles 8.6.6 and earlier. A separate Ninja Forms flaw (CVE-2026-90438) is fixed in 3.15.5, so 3.15.5 or later is the right target, not 3.15.4. WPC Product Bundles is fixed in 8.6.7.
Severity and context. The attackers leave four ways back in: a visible rogue administrator, a hidden administrator, a secret login URL that signs in as the site owner, and a file manager inside a fake plugin named wp-smart-thumbnails.
What to do. — click a step to check it off, click any code snippet to copy it
- Update both plugins now.
- Check the
mu-pluginsfolder, thewp-smart-thumbnailsplugin, and the database optionsfz_emer_done_v1andfz_emer_login_tokens. List administrators directly in the database, since one may be hidden from the dashboard. - If you find signs of compromise, clean up, reset administrator passwords and WordPress salts, and assess whether stored form submissions were accessed — they often hold names, emails and phone numbers.
3. Atlassian fixes critical unauthenticated file-access flaw in eight Data Center products (CVE-2026-21589)
What happened. Atlassian disclosed this flaw on October 5 — we covered it in yesterday's brief — and the official CVE record now gives exact fixed versions for every affected product, below. The path traversal flaw lets an unauthenticated attacker read specific files in the web application root of self-hosted Data Center products, provided they know the exact file path. It does not allow directory listing.
Severity and context. CVSS 4.0 score 9.3. No exploitation is confirmed, but an earlier Confluence path traversal flaw (CVE-2021-26086) is on CISA's KEV list — this bug class has a history of real-world attack once a path traversal is found. Atlassian has already fixed its cloud products; Data Center customers must act.
| Product (Data Center) | Fixed versions |
|---|---|
| Jira Software | 9.12.40, 10.3.26, 11.3.12 |
| Jira Service Management | 5.12.40, 10.3.26, 11.3.12 |
| Confluence | 9.2.26, 10.2.19 |
| Bitbucket | 9.4.26, 10.2.8, 10.5.1 |
| Bamboo | 10.2.24, 12.1.12 |
| Crowd | 6.3.7, 7.0.3, 7.1.7, 7.2.4 |
| Crucible and Fisheye | 4.9.15 |
What to do. — click a step to check it off
- Upgrade to the fixed version for your release line above, internet-facing instances first.
- If you cannot patch at once, restrict external access, or block ".." next to "/" or "\" in request paths at a WAF or reverse proxy, and review logs for such requests since October 5.
4. ASOS confirms customer data may have been accessed through a third-party messaging platform
What happened. On October 6, ASOS app users received unauthorized "ASOS HACKED" push notifications. ASOS said it was investigating unauthorized activity on third-party platforms it uses to communicate with customers and had restricted access to them. A group calling itself "Xuanye Group" claimed to have breached ASOS's Snowflake environment; Snowflake said it found no compromise of its own platform.
Who is affected. ASOS said names and contact details may have been accessed, but it does not believe payment card details or account passwords were. It has not said how many customers are involved.
What it means for customers. Names, emails and phone numbers are what fraudsters need for convincing phishing, such as fake refunds, delivery problems or security alerts. Customers should ignore links in unexpected messages and open the ASOS app or website directly instead; change their ASOS password if they've reused it elsewhere and turn on MFA where they can; and watch their bank and card statements, even though ASOS does not believe card data was involved.
What to do (organizations). — click a step to check it off
- Inventory every vendor that can message your customers or reach customer data.
- Confirm those vendor accounts use phishing-resistant MFA and are monitored for unusual exports or sends.
Compliance and personal data
This section is general information, not legal advice.
Also notable
Touchpoint's Take
Today's stories share one theme: attackers are abusing access that is trusted by design. A remote access gateway, an administrator's browser session, a vendor's messaging platform and a company's authorized access to a national register all fit that pattern, and misuse of each is easy to miss.
Behind today's numbers are shoppers, residents and employees who will now receive more convincing scams. Clear, prompt guidance for them is part of good incident response, not an afterthought.
What we would change in a security program:
- Patch edge appliances and self-hosted collaboration tools within days, especially product lines already exploited this year.
- Monitor vendor accounts and integrations for unusual volumes, not only failed logins. ASOS, Denmark's register and the FBI were all exposed through access that looked legitimate.
- Decide before an incident who owns notification decisions and how the 72-hour and state-law clocks are tracked.
If you would like help assessing your exposure to these issues or reviewing your third-party and breach-readiness controls, the Touchpoint Security team is available to talk.
Sources
- Canadian Centre for Cyber Security: SonicWall security advisory AV26-872 (earlier SMA 1000 zero-days)
- Help Net Security: SonicWall fixes pre-auth SSRF flaw in SMA 1000 appliances
- BleepingComputer: SonicWall warns of max severity SSRF flaw in SMA1000 gateways
- Patchstack: Four ways back in, the WordPress XSS campaign that hides its own admin account
- CVE record: CVE-2026-94504
- Patchstack database: Ninja Forms <= 3.15.4 unauthenticated stored XSS (CVE-2026-90438)
- BleepingComputer: Ninja Forms plugin flaw exploited to hack WordPress sites
- CVE record: CVE-2026-21589 (Atlassian CNA)
- Atlassian: CONFSERVER-104488
- Atlassian: JRASERVER-79546
- The Hacker News: Critical Atlassian flaw lets unauthenticated attackers read known files across 8 products
- BleepingComputer: Atlassian warns of critical file-access flaw in Jira, Confluence
- SecurityWeek: ASOS confirms cyberattack, data breach
- BleepingComputer: ASOS confirms data breach after "HACKED" in-app notifications
- Danish government press release (ufm.dk): Extensive unauthorized access to citizens' CPR data
- CISA Known Exploited Vulnerabilities catalog (data feed)
- CISA: Adds one Known Exploited Vulnerability to catalog (October 4)
- Nikkei notice 1547 and Nikkei notice 1554
- HHS press room and FTC press releases
- The Hacker News: FBI removes Accenture contractor after patch failure led to ShinyHunters breach
- SecurityWeek: FBI blames contractor's missed patch for ShinyHunters breach
- SecurityWeek: Chrome 155 update patches 247 vulnerabilities
- BleepingComputer: Nikkei discloses breaches of employees' Microsoft, Google email accounts
- The Record: Alleged ATM malware creator appears in Nebraska court after arrest
- The Hacker News: Denmark says attackers accessed CPR data for 8.8 million people
Not sure where you stand on any of this?
Our team is available to talk through your exposure to today's issues.