MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-10-09 · via BleepingComputer

SonicWall SMA1000 vulnerability exploited shortly after patch

Image via BleepingComputer
Image via BleepingComputer

Attackers have begun exploiting a critical SonicWall SMA1000 vulnerability, CVE-2026-102255, just days after a patch was released. The flaw affects the Appliance WorkPlace interface on certain models and could let unauthenticated remote users make the appliance send requests to internal services. A researcher said honeypot traffic showed attempts targeting an internal CouchDB service, while hundreds of SMA1000 devices remain exposed online.

Expanded Detail

The bug carries the highest severity rating and was fixed on Tuesday. It affects the Appliance WorkPlace interface on SMA1000 models 6210, 7210, and 8200v, while leaving the SMA 100 Series and SSL-VPN on SonicWall firewalls unaffected. If abused, an unauthenticated remote actor could make the appliance send requests for them, potentially reaching internal services and carrying out unauthorized actions.

Previdian's Ryan Dewhurst said honeypot traffic matched the flaw. The probes used a crafted OPTIONS request against WorkPlace Extraweb, aiming at an internal CouchDB service on localhost and trying to reach a design document's rewrite function with admin:admin credentials. The same interface was hit by earlier SSRF bugs in July and September 2026, though this exploit method differs. More than 400 SMA1000 devices remain internet-exposed, per Shadowserver.

Count words? First para: The(1) bug2 carries3 the4 highest5 severity6 rating7 and8 was9 fixed10 on11 Tuesday12. It13 affects14 the15 Appliance16 WorkPlace17 interface18 on19 SMA100020 models21 6210,22 7210,23 and24 8200v,25 while26 leaving27 the28 SMA29 10030 Series31 and32 SSL-VPN33 on34 SonicWall35 firewalls36 unaffected37. If38 abused39, an40 unauthenticated41 remote42 actor43 could44 make45 the46 appliance47 send48 requests49 for50 them51, potentially52 reaching53 internal54 services55 and56 carrying57 out58 unauthorized59 actions60. First 60. Second: Previdian's1 Ryan2 Dewhurst3 said4 honeypot5 traffic6 matched7 the8 fla

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Citrix Discloses Severe NetScaler Flaw Allowing Remote Code Execution · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Max severity SonicWall SMA1000 flaw now exploited in attacks.” Browse more stories.