Max severity SonicWall SMA1000 flaw now exploited in attacks
Attackers exploit max-severity SonicWall SMA1000 flaw CVE-2026-102255 three days after patch; Previdian honeypots captured matching exploitation attempts.
Previdian honeypots detected exploitation attempts against CVE-2026-102255, a maximum-severity flaw in the Appliance WorkPlace interface of SonicWall SMA1000 6210, 7210, and 8200v models. Crafted OPTIONS requests target the internal CouchDB service at 127.0.0.1:5984, traversing design documents and attempting admin:admin basic auth, letting remote unauthenticated attackers issue requests on the appliance's behalf. Shadowserver tracks more than 400 exposed SMA1000 appliances, widely used by MSSPs, corporations, and government agencies; CISA has added 19 SonicWall flaws to its KEV catalog, 13 tied to ransomware gangs.
- Remote unauthenticated attackers abuse WorkPlace interface to reach internal CouchDB and perform unauthorized operations.
- Previdian honeypots observed exploitation attempts three days after patch release; compromise success unconfirmed.
- Shadowserver counts 400+ exposed SMA1000 appliances used by MSSPs, large firms, and government.
- SonicWall has had 19 flaws added to CISA KEV, 13 linked to ransomware gangs.
Vulnerabilities mentionedAll →
- CVE-2026-10225510.0—Pre-auth SSRF in SonicWall SMA1000 Work Place interfacepublished · SonicWall SMA1000 Appliance (Work Place interface)
- CVE-2026-1540910.07%Unauthenticated SSRF in SonicWall SMA1000 Appliancespublished · SonicWall SMA1000 Appliances (SMA 6210 firmware)
Full article445 words · extracted from bleepingcomputer.com · click to collapse

Attackers are exploiting a maximum-severity vulnerability in SonicWall SMA1000 appliances (CVE-2026-102255) that was patched on Tuesday, three days ago.
Tracked as CVE-2026-102255, the flaw affects the Appliance WorkPlace interface on SMA1000 6210, 7210, and 8200v models, but does not affect the SMA 100 Series product line or SSL-VPN running on SonicWall firewalls.
"By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations," SonicWall explained.
While SonicWall has not yet flagged this vulnerability as actively exploited in its Tuesday advisory, Previdian founder and security researcher Ryan Dewhurst told BleepingComputer on Friday that the company's honeypot network has detected exploitation attempts consistent with the CVE-2026-102255 flaw.
"The requests targeted the WorkPlace Extraweb interface, using a crafted OPTIONS request to reach the appliance's internal CouchDB service at 127.0.0.1:5984. The payload attempted to traverse into a CouchDB design document and invoke its _rewrite function, while supplying an HTTP Basic Authorization header containing the credentials admin:admin," Dewhurst told BleepingComputer.
"It affects the same WorkPlace interface targeted by earlier SSRF vulnerabilities disclosed in July and September 2026. However, the October vulnerability uses a different exploitation technique.
Dewhurst also added that while this activity is consistent with active exploitation attempts, Previdian has not yet established "whether those attempts would have successfully compromised any systems."
While Internet threat watchdog Shadowserver now tracks more than 400 SMA1000 appliances exposed online, there is no information on how many are honeypots or have already been patched against CVE-2026-102255 attacks.

SMA1000 enterprise-grade secure remote access gateways are often targeted because Managed Service Providers (MSSPs), many large corporations, and government agencies use them for VPN access to internal apps and corporate networks.
For instance, in July, threat actors abused two SMA1000 zero-days (CVE-2026-15409 and CVE-2026-15410) for weeks to install custom Sou5, OrangeTail, and RootRun malware on vulnerable VPN appliances.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) later linked some of these attacks to ransomware gangs.
Last month, SonicWall also warned customers that attackers were chaining two new zero-days (CVE-2026-83548 and CVE-2026-83549) in the wild to execute remote code on vulnerable SMA1000 gateways.
Over the last four years, CISA has added 19 SonicWall vulnerabilities to its catalog of actively exploited flaws, flagging 13 of them as used by ransomware gangs.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.