Skip to content
InYourGeek
visiteur@inyourgeek — shell
↹ compléter↑↓ historique⏎ ouvrirhelp
FR
Security· 3 min read

SonicWall SMA1000: max-severity flaw CVE-2026-102255 already targeted

Three days after SonicWall patched it, the maximum-severity flaw in its SMA1000 gateways is already drawing exploitation attempts. These boxes guard the internal networks of big companies and government agencies, and their previous flaws fed ransomware gangs.

A SonicWall remote access gateway in a server rack, with network requests bouncing off it towards an internal database

According to Bleeping Computer, attackers have been going after CVE-2026-102255 since Friday, October 9, 2026. The flaw affects SonicWall’s SMA1000 remote access gateways. SonicWall patched it on Tuesday, three days earlier. So far the exploitation rests on a single source: a honeypot network whose observations the outlet reported. Treat it as exploitation spotted by a third party that the vendor hasn’t yet confirmed.

Which devices are affected

The flaw sits in the Appliance WorkPlace interface of the SMA1000 6210, 7210 and 8200v models. According to Bleeping Computer, it doesn’t affect the SMA 100 series or the SSL-VPN built into SonicWall firewalls. If your remote access runs through one of those two products, this particular bullet has someone else’s name on it.

SonicWall describes the flaw as unauthenticated and remotely exploitable. An attacker can get the box to send requests on their behalf, reach internal functions and carry out unauthorized operations there. That’s how an SSRF (server-side request forgery) flaw works: the server becomes the attacker’s errand boy, fetching things from places the attacker was never meant to reach.

What the honeypots saw

The advisory SonicWall published on Tuesday reported no active exploitation. On Friday, a company called Previdian told Bleeping Computer that its honeypot network had logged attempts matching this flaw. The requests targeted the WorkPlace Extraweb interface. A crafted OPTIONS request tried to reach the box’s internal CouchDB service at 127.0.0.1:5984. The payload then tried to climb up to a CouchDB design document and call its _rewrite function, with the username and password admin:admin in an HTTP Basic authentication header. Yes, admin:admin. Apparently still worth a shot in 2026.

Previdian says it doesn’t yet know whether these attempts would have managed to compromise a system. According to the researcher, the flaw sits in the same WorkPlace interface as the SSRF flaws disclosed in July and September 2026, but uses a different exploitation technique. Same door, new crowbar.

Nobody knows yet how many devices are exposed. Shadowserver tracks more than 400 SMA1000 devices reachable from the Internet. How many of them are honeypots, and how many are already patched, is anyone’s guess.

Why you shouldn’t wait

The context alone makes this urgent. Bleeping Computer points out that SMA1000s are prime targets because managed service providers, large enterprises and government agencies use them for VPN access to their internal applications and networks. Compromise the gateway and you’re already past the front door.

Recent history backs this up. In July, attackers exploited two SMA1000 zero-days (CVE-2026-15409 and CVE-2026-15410) for weeks to install the Sou5, OrangeTail and RootRun malware. CISA, the US cybersecurity agency, later linked some of those attacks to ransomware gangs. In September, SonicWall warned that attackers were chaining two more zero-days (CVE-2026-83548 and CVE-2026-83549) to execute code remotely on the same gateways. Over the past four years, CISA has added 19 SonicWall flaws to its catalog of actively exploited vulnerabilities, and ransomware groups used 13 of them. At this point, those crews could apply for a loyalty card.

This time the patch arrived before any confirmed compromise, which wasn’t true of the summer’s zero-days. If you run an SMA1000 6210, 7210 or 8200v, apply the patch from SonicWall’s Tuesday advisory right away. Also check your logs for OPTIONS requests sent to the WorkPlace Extraweb interface since October 6.

It now takes three days to get from a patch to the first attacks. Patch Tuesday, exploit Friday: if that advisory is still sitting unread in your inbox, rest assured someone else has already read it for you.

Sources (1)

Written with AI assistance from the sources cited above, then reviewed and approved before publication by Sébastien Soulier.