SonicWall SMA1000 SSRF bug CVE-2026-102255 under active attack days after patch
Security researcher Ryan Dewhurst told BleepingComputer that his Previdian honeypots detected exploitation attempts against CVE-2026-102255, a maximum-severity SonicWall SMA1000 vulnerability patched three days earlier. The flaw affects the Appliance WorkPlace interface on SMA1000 6210, 7210 and 8200v models, letting unauthenticated attackers reach internal functionality via a crafted request to the appliance's internal CouchDB service. Shadowserver counts over 400 SMA1000 appliances still exposed online, though it's unclear how many remain unpatched.
GoKawiil's interpretation of the reporting above, not reported fact.
The short gap between disclosure and exploitation suggests attackers are quickly reverse-engineering patches to target organizations that haven't yet updated their appliances. Because SMA1000 devices often sit at the edge of enterprise networks providing remote access, a successful SSRF exploit could let attackers pivot into internal systems, making rapid patching especially urgent. Dewhurst notes it's still unconfirmed whether any attempts have actually compromised systems, so the real-world impact remains uncertain.
- CVE-2026-102255 is a maximum-severity SSRF flaw in SonicWall SMA1000's WorkPlace interface, patched just three days before exploitation attempts were observed.
- Researcher Ryan Dewhurst's honeypots detected crafted requests targeting the appliance's internal CouchDB service using default admin:admin credentials.
- Over 400 SMA1000 appliances remain exposed online according to Shadowserver, with unknown patch status for many of them.
Source: bleepingcomputer.com, 2026-10-09
Published there as: “Max severity SonicWall SMA1000 flaw now exploited in attacks”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.