Back to Feed
VulnerabilitiesOct 9, 2026

Max severity SonicWall SMA1000 flaw now exploited in attacks

SonicWall SMA1000 vulnerability (CVE-2026-102255) is being exploited in attacks.

Summary

Attackers are actively exploiting a critical vulnerability, CVE-2026-102255, in SonicWall SMA1000 appliances shortly after a patch was released. The flaw affects the Appliance WorkPlace interface and allows unauthenticated remote attackers to issue requests on behalf of the appliance. This exploitation follows a pattern of previous vulnerabilities in SMA1000 devices, some of which have been linked to ransomware gangs by CISA.

Full text

Max severity SonicWall SMA1000 flaw now exploited in attacks By Sergiu Gatlan October 9, 2026 08:32 AM 0 Attackers are exploiting a maximum-severity vulnerability in SonicWall SMA1000 appliances (CVE-2026-102255) that was patched on Tuesday, three days ago. Tracked as CVE-2026-102255, the flaw affects the Appliance WorkPlace interface on SMA1000 6210, 7210, and 8200v models, but does not affect the SMA 100 Series product line or SSL-VPN running on SonicWall firewalls. "By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations," SonicWall explained. While SonicWall has not yet flagged this vulnerability as actively exploited in its Tuesday advisory, Previdian founder and security researcher Ryan Dewhurst told BleepingComputer on Friday that the company's honeypot network has detected exploitation attempts consistent with the CVE-2026-102255 flaw. "The requests targeted the WorkPlace Extraweb interface, using a crafted OPTIONS request to reach the appliance's internal CouchDB service at 127.0.0.1:5984. The payload attempted to traverse into a CouchDB design document and invoke its _rewrite function, while supplying an HTTP Basic Authorization header containing the credentials admin:admin," Dewhurst told BleepingComputer. "It affects the same WorkPlace interface targeted by earlier SSRF vulnerabilities disclosed in July and September 2026. However, the October vulnerability uses a different exploitation technique. Dewhurst also added that while this activity is consistent with active exploitation attempts, Previdian has not yet established "whether those attempts would have successfully compromised any systems." While Internet threat watchdog Shadowserver now tracks more than 400 SMA1000 appliances exposed online, there is no information on how many are honeypots or have already been patched against CVE-2026-102255 attacks. SMA1000 instances exposed online (Shadowserver) ​SMA1000 enterprise-grade secure remote access gateways are often targeted because Managed Service Providers (MSSPs), many large corporations, and government agencies use them for VPN access to internal apps and corporate networks. For instance, in July, threat actors abused two SMA1000 zero-days (CVE-2026-15409 and CVE-2026-15410) for weeks to install custom Sou5, OrangeTail, and RootRun malware on vulnerable VPN appliances. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) later linked some of these attacks to ransomware gangs. Last month, SonicWall also warned customers that attackers were chaining two new zero-days (CVE-2026-83548 and CVE-2026-83549) in the wild to execute remote code on vulnerable SMA1000 gateways. Over the last four years, CISA has added 19 SonicWall vulnerabilities to its catalog of actively exploited flaws, flagging 13 of them as used by ransomware gangs. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat Related Articles: SonicWall warns of max severity SSRF flaw in SMA1000 gatewaysSonicWall warns of actively exploited SMA1000 zero-day flawsSonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch nowCISA: SonicWall SMA1000 flaws now exploited by ransomware gangsSonicwall warns of new SMA1000 zero-day exploited in attacks

Indicators of Compromise

  • cve — CVE-2026-102255
  • cve — CVE-2026-15409
  • cve — CVE-2026-15410
  • cve — CVE-2026-83548
  • cve — CVE-2026-83549

Entities

SMA1000 (product)SonicWall (vendor)ransomware gangs (threat_actor)VPN (technology)Appliance WorkPlace (product)