SonicWall SMA1000 Flaw CVE-2026-102255 Exploited After Patch
Previdian's honeypot network detected exploitation attempts against SonicWall SMA1000 appliances, three days after CVE-2026-102255 was patched.
Attackers have been detected attempting to exploit CVE-2026-102255, a maximum-severity vulnerability in SonicWall SMA1000 appliances that was patched three days earlier, according to bleepingcomputer.com.
The flaw affects the Appliance WorkPlace interface on SMA1000 6210, 7210, and 8200v models. It does not affect the SMA 100 Series product line or SSL-VPN running on SonicWall firewalls.
Previdian founder and security researcher Ryan Dewhurst said the company's honeypot network detected exploitation attempts consistent with CVE-2026-102255. The attempts targeted the WorkPlace Extraweb interface using a crafted OPTIONS request to reach the appliance's internal CouchDB service at 127.0.0.1:5984.
Dewhurst said Previdian has not yet established whether the attempts would have successfully compromised any systems. SonicWall has not flagged the vulnerability as actively exploited in its Tuesday advisory.
Earlier SMA1000 attacks
The flaw affects the same WorkPlace interface targeted by earlier SSRF vulnerabilities disclosed in July and September 2026, though the October vulnerability uses a different exploitation technique. Shadowserver now tracks more than 400 SMA1000 appliances exposed online.
In July, threat actors abused two SMA1000 zero-days (CVE-2026-15409 and CVE-2026-15410) for weeks to install custom Sou5, OrangeTail, and RootRun malware on vulnerable VPN appliances. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) later linked some of those attacks to ransomware gangs. Last month, SonicWall warned customers that attackers were chaining two new zero-days (CVE-2026-83548 and CVE-2026-83549) in the wild to execute remote code on vulnerable SMA1000 gateways.
Quick answers
What is CVE-2026-102255?
It is a maximum-severity vulnerability in SonicWall SMA1000 appliances, affecting the Appliance WorkPlace interface on SMA1000 6210, 7210, and 8200v models.
Which SonicWall products are affected by CVE-2026-102255?
The flaw affects the Appliance WorkPlace interface on SMA1000 6210, 7210, and 8200v models. It does not affect the SMA 100 Series product line or SSL-VPN running on SonicWall firewalls.
Has CVE-2026-102255 been actively exploited?
Previdian's honeypot network detected exploitation attempts consistent with the flaw, but Previdian has not yet established whether the attempts would have successfully compromised any systems. SonicWall has not flagged the vulnerability as actively exploited in its Tuesday advisory.