SonicWall SMA1000 vulnerability exploited shortly after patch

Attackers have begun exploiting a critical SonicWall SMA1000 vulnerability, CVE-2026-102255, just days after a patch was released. The flaw affects the Appliance WorkPlace interface on certain models and could let unauthenticated remote users make the appliance send requests to internal services. A researcher said honeypot traffic showed attempts targeting an internal CouchDB service, while hundreds of SMA1000 devices remain exposed online.
The bug carries the highest severity rating and was fixed on Tuesday. It affects the Appliance WorkPlace interface on SMA1000 models 6210, 7210, and 8200v, while leaving the SMA 100 Series and SSL-VPN on SonicWall firewalls unaffected. If abused, an unauthenticated remote actor could make the appliance send requests for them, potentially reaching internal services and carrying out unauthorized actions.
Previdian's Ryan Dewhurst said honeypot traffic matched the flaw. The probes used a crafted OPTIONS request against WorkPlace Extraweb, aiming at an internal CouchDB service on localhost and trying to reach a design document's rewrite function with admin:admin credentials. The same interface was hit by earlier SSRF bugs in July and September 2026, though this exploit method differs. More than 400 SMA1000 devices remain internet-exposed, per Shadowserver.
Count words? First para: The(1) bug2 carries3 the4 highest5 severity6 rating7 and8 was9 fixed10 on11 Tuesday12. It13 affects14 the15 Appliance16 WorkPlace17 interface18 on19 SMA100020 models21 6210,22 7210,23 and24 8200v,25 while26 leaving27 the28 SMA29 10030 Series31 and32 SSL-VPN33 on34 SonicWall35 firewalls36 unaffected37. If38 abused39, an40 unauthenticated41 remote42 actor43 could44 make45 the46 appliance47 send48 requests49 for50 them51, potentially52 reaching53 internal54 services55 and56 carrying57 out58 unauthorized59 actions60. First 60. Second: Previdian's1 Ryan2 Dewhurst3 said4 honeypot5 traffic6 matched7 the8 fla