Skip to content

SecurityNot yet confirmed elsewhere1 publisher2 min readPublished

Honeypots log exploitation attempts against SonicWall SMA1000 flaw three days after patch

Attackers began targeting SonicWall's maximum-severity SMA1000 flaw CVE-2026-102255 within three days of its patch, Previdian's honeypots show. SonicWall's advisory had not called it exploited by Friday, so owners waiting on that label are patching behind the attackers.

The Watch · Security desk

How we use AISend a correction

What happened

  • The flaw sits in the Appliance WorkPlace interface on SMA1000 6210, 7210 and 8200v models; the SMA 100 Series and SSL-VPN on SonicWall firewalls are not affected.
  • Previdian has not yet established whether any of the logged attempts would have compromised a real system.
  • Shadowserver tracks more than 400 SMA1000 appliances exposed online, a figure that includes an unknown number of honeypots and patched units.
  • CVE-2026-102255 is the fifth SMA1000 flaw attackers have gone after since July, spread across three separate rounds.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision Attempts arrived three days after the fix shipped, so an SMA1000 owner on a monthly change window would leave the gateway open for weeks after attackers showed up.
  • exposure Because these gateways front VPN access for MSSPs, large companies and government agencies, a working request-forgery path exposes internal services at those organisations to an outsider with no credentials.
  • precedent July's SMA1000 zero-days ended up in intrusions CISA linked to ransomware gangs; a reliable exploit for this bug would be expected to travel the same way.

The traffic Previdian logged is a server-side request forgery aimed at a database that should only answer to the appliance itself [5][1]. "The requests targeted the WorkPlace Extraweb interface, using a crafted OPTIONS request to reach the appliance's internal CouchDB service at 127.0.0.1:5984. The payload attempted to traverse into a CouchDB design document and invoke its _rewrite function, while supplying an HTTP Basic Authorization header containing the credentials admin:admin," Dewhurst told BleepingComputer [2].

The attacker needs no login on the gateway. SonicWall said a remote unauthenticated attacker could use the flaw to "direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations" [5]. In Previdian's capture, the request is aimed at the appliance's own loopback address, where CouchDB listens on port 5984 [2]. The payload then reaches for a design document's _rewrite function and offers admin:admin, a default-style login, to the internal database [2].

The WorkPlace code has been hit before. Dewhurst said the bug "affects the same WorkPlace interface targeted by earlier SSRF vulnerabilities disclosed in July and September 2026," though the October flaw uses a different exploitation technique [7]. In July, attackers used two SMA1000 zero-days, CVE-2026-15409 and CVE-2026-15410, for weeks to install Sou5, OrangeTail and RootRun malware [10]. Last month, SonicWall warned that attackers were chaining CVE-2026-83548 and CVE-2026-83549 in the wild to run code on SMA1000 gateways [12].

That makes three rounds against SMA1000 since July [15]. Previdian described the requests and the payload but not who sent them, so whether one crew is behind all three rounds is not public [1][2].

SonicWall flaws that reach CISA's list tend to end up with ransomware crews [14]. In the past four years, 19 SonicWall bugs have gone into CISA's exploited-vulnerabilities catalog, and the agency flagged 13 of them, about 68 percent, as used by ransomware gangs [13][14].

What to watch

  • SonicWall revising its CVE-2026-102255 advisory to mark the flaw actively exploited, or CISA adding it to its exploited-vulnerabilities catalog.
  • Confirmation from Previdian or an incident responder that the CouchDB _rewrite request compromised a production SMA1000 appliance.
  • Shadowserver figures showing how many of the 400-plus exposed SMA1000 appliances still run unpatched builds.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence50
Adoption30
Hype gap+30
Incentives
Insufficient
Confidence55
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Ryan Dewhurst, founder of Previdian, told BleepingComputer on Friday that Previdian's honeypot network detected exploitation attempts consistent with CVE-2026-102255.

    ReportedSupportedSource: Ryan Dewhurst, Previdian, to BleepingComputer2 sources— create a free account to open themView cited source
  2. [2]

    "The requests targeted the WorkPlace Extraweb interface, using a crafted OPTIONS request to reach the appliance's internal CouchDB service at 127.0.0.1:5984. The payload attempted to traverse into a CouchDB design document and invoke its _rewrite function, while supplying an HTTP Basic Authorization header containing the credentials admin:admin,"

    ReportedSupportedSource: Ryan Dewhurst, Previdian, to BleepingComputer2 sources— create a free account to open themView cited source
  3. [3]

    Dewhurst said the activity is consistent with active exploitation attempts, but Previdian has not yet established "whether those attempts would have successfully compromised any systems."

    ReportedSupportedSource: Ryan Dewhurst, Previdian, to BleepingComputer2 sources— create a free account to open themView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. bleepingcomputer.com

    1 article · October 9, 2026

    Max severity SonicWall SMA1000 flaw now exploited in attacks

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories