SonicWall SMA1000 max-severity flaw now exploited
Attackers are already targeting CVE-2026-102255, a maximum-severity vulnerability in SonicWall's SMA1000 secure remote access appliances. SonicWall patched the flaw on Tuesday, so exploitation attempts began within three days of the fix.
The vulnerability sits in the Appliance WorkPlace interface of the SMA1000 6210, 7210 and 8200v models. The SMA 100 Series product line is not affected, and neither is the SSL-VPN functionality on SonicWall firewalls.
In its advisory, SonicWall said that "a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations." This behaviour is typical of server-side request forgery (SSRF), where an attacker tricks a server into sending requests to systems the attacker cannot reach directly. Our earlier report covers the original SonicWall advisory in more detail.
Honeypots catch the first attempts
As of Tuesday, SonicWall's advisory did not list the flaw as exploited. That changed on Friday, when Ryan Dewhurst, founder of Previdian and a security researcher, told BleepingComputer that the company's honeypot network had recorded exploitation attempts matching CVE-2026-102255.
He described what the attackers were doing:
"The requests targeted the WorkPlace Extraweb interface, using a crafted OPTIONS request to reach the appliance's internal CouchDB service at 127.0.0.1:5984. The payload attempted to traverse into a CouchDB design document and invoke its _rewrite function, while supplying an HTTP Basic Authorization header containing the credentials admin:admin."
CouchDB is a database service that runs inside the appliance. The address 127.0.0.1 is the local loopback, so the service should only be reachable from the device itself. The attackers were trying to reach that internal service through the exposed web interface and then use default-style credentials on it.
Dewhurst said the same WorkPlace interface was the target of earlier SSRF vulnerabilities disclosed in July and September 2026. The October flaw is exploited with a different technique, he added.
He was careful about the results. The activity is consistent with active exploitation attempts, but Previdian has not yet established "whether those attempts would have successfully compromised any systems."
How many devices are at risk
Shadowserver, a non-profit that monitors threats on the internet, currently tracks more than 400 SMA1000 appliances exposed online. It is not known how many of them are honeypots, or how many have already received the CVE-2026-102255 patch.
The number is small compared to some other edge devices, but the profile of SMA1000 users raises the stakes. These enterprise-grade gateways provide VPN access to internal applications and corporate networks. Managed service providers, many large corporations and government agencies rely on them, which is why attackers keep coming back to them.
A busy year for SMA1000 attacks
This is the third wave of SMA1000 attacks this year.
In July, threat actors exploited two zero-days, CVE-2026-15409 and CVE-2026-15410, for weeks. They used them to install custom malware families named Sou5, OrangeTail and RootRun on vulnerable VPN appliances. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) later linked some of those attacks to ransomware gangs.
In September, SonicWall warned customers that attackers were chaining two more zero-days, CVE-2026-83548 and CVE-2026-83549, to run remote code on vulnerable SMA1000 gateways.
The longer record is not much better. Over the past four years, CISA has added 19 SonicWall vulnerabilities to its Known Exploited Vulnerabilities catalog, a list of flaws confirmed as used in real attacks. CISA flagged 13 of them as used by ransomware gangs.
Admins running SMA1000 6210, 7210 or 8200v appliances should apply the Tuesday update if they have not already, and review logs for unusual requests to the WorkPlace interface.
Our Take
The timeline here is the main lesson. A patch on Tuesday and attack traffic by Friday leaves little room for monthly maintenance windows. For VPN gateways and other edge devices, a three-day gap between fix and exploitation suggests that "patch within days" is now a working requirement rather than a best practice.
The pattern also matters. Attackers have now gone after the same WorkPlace interface in July, September and October, each time with a different technique. This suggests someone is studying this component closely, and it would not be surprising if more flaws in it turn up. The same pressure is visible across the sector, from compromised Fortinet devices to the recent Citrix NetScaler zero-day.
It is worth watching whether SonicWall updates its advisory to confirm exploitation, whether CISA adds CVE-2026-102255 to its catalog, and whether any successful compromises are linked to ransomware groups, as happened after the July attacks.
