Just three days after SonicWall shipped a patch for a maximum-severity vulnerability in its SMA1000 secure remote access appliances, attackers have started scanning for and exploiting the flaw in the wild.The vulnerability, tracked as CVE-2026-102255 and carrying a perfect CVSS score of 10.0, is a pre-authentication server-side request forgery (SSRF) bug living inside the Appliance WorkPlace interface. Because it requires no login to trigger, any remote attacker can send a crafted request to a vulnerable device and force it to relay traffic to internal services that should never be reachable from outside.SonicWall released hotfixes on October 7 alongside three other patches and, at the time, said it had found no evidence the flaw was being actively exploited. By Friday, that had changed.How the Exploit WorksRyan Dewhurst, founder of security firm Previdian, said that his company's honeypot network had picked up exploitation attempts matching the CVE-2026-102255 attack pattern.
The requests were not subtle.Attackers sent a crafted OPTIONS request to the WorkPlace Extraweb interface, using it to tunnel through to the appliance's internal CouchDB service running on localhost at port 5984. From there, the payload attempted to navigate into a CouchDB design document and call its \_rewrite function, while passing an HTTP Basic Authorization header carrying the credentials admin:admin.It is an opportunistic probe, but it tells you something: whoever is sending these requests already has a working technique and is scanning for any devices that have not yet been patched.Dewhurst noted that while the activity is consistent with active exploitation attempts, Previdian has not confirmed whether any of those attempts actually compromised a system.This also is not a copy of the SSRF attacks that hit SMA1000 devices in July or September. CVE-2026-102255 targets the same WorkPlace interface, but uses a different technique than the zero-days disclosed in those earlier incidents.Who Is ExposedThe flaw affects SMA1000 models 6210, 7210, and 8200v running firmware versions 12.4.3-03526 and 12.5.0-02952 and older.
SonicWall confirmed that neither the SMA 100 Series product line nor SSL-VPN functionality on SonicWall firewalls are affected.Internet threat monitoring organization Shadowserver currently tracks more than 400 SMA1000 appliances with public-facing exposure. That figure does not separate out honeypots or already-patched devices, so the real pool of vulnerable targets could be smaller, though the number is still of importance.SMA1000 gateways sit at the front door of corporate and government networks. Managed Service Providers, large enterprises, and government agencies rely on them to extend VPN access to internal applications for remote employees.
That makes them a high-value target for nation-state actors and financially motivated cybercriminals alike.A Pattern That Keeps RepeatingCVE-2026-102255 is the third time in 2026 alone that SonicWall has patched a CVSS 10.0 pre-authentication SSRF flaw in the WorkPlace interface that requires no login to exploit. The two that came before it were both turned into weapons before organizations could patch at scale.In July, threat actors spent weeks exploiting two SMA1000 zero-days, CVE-2026-15409 and CVE-2026-15410, to plant custom malware families called Sou5, OrangeTail, and RootRun on compromised appliances. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) later tied several of those intrusions to ransomware operators.In September, SonicWall confirmed attackers were chaining two fresh zero-days, CVE-2026-83548 and CVE-2026-83549, to achieve remote code execution on unpatched SMA1000 devices.Zooming out further, CISA has added 19 SonicWall vulnerabilities to its Known Exploited Vulnerabilities catalog over the past four years.
Thirteen of them have been flagged as actively used in ransomware attacks.The October hotfix batch addressed three additional vulnerabilities beyond CVE-2026-102255. CVE-2026-102256, rated CVSS 7.8, is a post-authentication OS command injection flaw that could let an attacker with administrator credentials execute arbitrary commands on the appliance. CVE-2026-102257, rated 7.2, is a Zip Slip path traversal flaw in the Appliance Management Console that could allow file extraction outside the intended directory and potentially enable remote code execution.
CVE-2026-102258, rated 5.5, is a stored cross-site scripting flaw in the same management console that could allow a logged-in administrator to inject and execute JavaScript.SonicWall credited researcher Benoît Sevens with reporting CVE-2026-102255 and CVE-2026-102256, and Brian Mariani of DigitalCanion SA for the other two, one of which was submitted through Trend Micro's Zero Day Initiative.SonicWall has urged all SMA1000 customers to apply the hotfixes immediately and has stated there are no alternative mitigations available for these vulnerabilities. Tags: CVE 2026 sma1000 SonicWall vulnerabilities and exploits