SecurityNot yet confirmed elsewhere1 publisher2 min readPublished
Honeypots log exploitation attempts against SonicWall SMA1000 flaw three days after patch
Attackers began targeting SonicWall's maximum-severity SMA1000 flaw CVE-2026-102255 within three days of its patch, Previdian's honeypots show. SonicWall's advisory had not called it exploited by Friday, so owners waiting on that label are patching behind the attackers.
The Watch · Security desk
What happened
- The flaw sits in the Appliance WorkPlace interface on SMA1000 6210, 7210 and 8200v models; the SMA 100 Series and SSL-VPN on SonicWall firewalls are not affected.
- Previdian has not yet established whether any of the logged attempts would have compromised a real system.
- Shadowserver tracks more than 400 SMA1000 appliances exposed online, a figure that includes an unknown number of honeypots and patched units.
- CVE-2026-102255 is the fifth SMA1000 flaw attackers have gone after since July, spread across three separate rounds.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision Attempts arrived three days after the fix shipped, so an SMA1000 owner on a monthly change window would leave the gateway open for weeks after attackers showed up.
- exposure Because these gateways front VPN access for MSSPs, large companies and government agencies, a working request-forgery path exposes internal services at those organisations to an outsider with no credentials.
- precedent July's SMA1000 zero-days ended up in intrusions CISA linked to ransomware gangs; a reliable exploit for this bug would be expected to travel the same way.
The traffic Previdian logged is a server-side request forgery aimed at a database that should only answer to the appliance itself [5][1]. "The requests targeted the WorkPlace Extraweb interface, using a crafted OPTIONS request to reach the appliance's internal CouchDB service at 127.0.0.1:5984. The payload attempted to traverse into a CouchDB design document and invoke its _rewrite function, while supplying an HTTP Basic Authorization header containing the credentials admin:admin," Dewhurst told BleepingComputer [2].
The attacker needs no login on the gateway. SonicWall said a remote unauthenticated attacker could use the flaw to "direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations" [5]. In Previdian's capture, the request is aimed at the appliance's own loopback address, where CouchDB listens on port 5984 [2]. The payload then reaches for a design document's _rewrite function and offers admin:admin, a default-style login, to the internal database [2].
The WorkPlace code has been hit before. Dewhurst said the bug "affects the same WorkPlace interface targeted by earlier SSRF vulnerabilities disclosed in July and September 2026," though the October flaw uses a different exploitation technique [7]. In July, attackers used two SMA1000 zero-days, CVE-2026-15409 and CVE-2026-15410, for weeks to install Sou5, OrangeTail and RootRun malware [10]. Last month, SonicWall warned that attackers were chaining CVE-2026-83548 and CVE-2026-83549 in the wild to run code on SMA1000 gateways [12].
That makes three rounds against SMA1000 since July [15]. Previdian described the requests and the payload but not who sent them, so whether one crew is behind all three rounds is not public [1][2].
SonicWall flaws that reach CISA's list tend to end up with ransomware crews [14]. In the past four years, 19 SonicWall bugs have gone into CISA's exploited-vulnerabilities catalog, and the agency flagged 13 of them, about 68 percent, as used by ransomware gangs [13][14].
What to watch
- SonicWall revising its CVE-2026-102255 advisory to mark the flaw actively exploited, or CISA adding it to its exploited-vulnerabilities catalog.
- Confirmation from Previdian or an incident responder that the CouchDB _rewrite request compromised a production SMA1000 appliance.
- Shadowserver figures showing how many of the 400-plus exposed SMA1000 appliances still run unpatched builds.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence50
- Adoption30
- Hype gap+30
- Incentives
- Insufficient
- Confidence55
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Ryan Dewhurst, founder of Previdian, told BleepingComputer on Friday that Previdian's honeypot network detected exploitation attempts consistent with CVE-2026-102255.
ReportedSupportedSource: Ryan Dewhurst, Previdian, to BleepingComputer2 sources— create a free account to open themView cited source - [2]
"The requests targeted the WorkPlace Extraweb interface, using a crafted OPTIONS request to reach the appliance's internal CouchDB service at 127.0.0.1:5984. The payload attempted to traverse into a CouchDB design document and invoke its _rewrite function, while supplying an HTTP Basic Authorization header containing the credentials admin:admin,"
ReportedSupportedSource: Ryan Dewhurst, Previdian, to BleepingComputer2 sources— create a free account to open themView cited source - [3]
Dewhurst said the activity is consistent with active exploitation attempts, but Previdian has not yet established "whether those attempts would have successfully compromised any systems."
ReportedSupportedSource: Ryan Dewhurst, Previdian, to BleepingComputer2 sources— create a free account to open themView cited source - [4]
CVE-2026-102255 affects the Appliance WorkPlace interface on SMA1000 6210, 7210 and 8200v models and does not affect the SMA 100 Series or SSL-VPN running on SonicWall firewalls.
- [5]
"By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations,"
- [6]
SonicWall had not flagged CVE-2026-102255 as actively exploited in its Tuesday advisory as of BleepingComputer's Friday report.
- [7]
"It affects the same WorkPlace interface targeted by earlier SSRF vulnerabilities disclosed in July and September 2026." Dewhurst added that the October vulnerability uses a different exploitation technique.
- [8]
Shadowserver tracks more than 400 SMA1000 appliances exposed online; there is no information on how many are honeypots or already patched against CVE-2026-102255.
- [9]
SMA1000 secure remote access gateways are often targeted because MSSPs, many large corporations and government agencies use them for VPN access to internal apps and corporate networks.
- [10]
In July, threat actors abused two SMA1000 zero-days, CVE-2026-15409 and CVE-2026-15410, for weeks to install custom Sou5, OrangeTail and RootRun malware on vulnerable VPN appliances.
- [11]
CISA later linked some of the July SMA1000 attacks to ransomware gangs.
- [12]
Last month, SonicWall warned customers that attackers were chaining two zero-days, CVE-2026-83548 and CVE-2026-83549, in the wild to execute remote code on vulnerable SMA1000 gateways.
- [13]
Over the last four years, CISA has added 19 SonicWall vulnerabilities to its catalog of actively exploited flaws, flagging 13 of them as used by ransomware gangs.
- [14]
About 68 percent of SonicWall flaws in CISA's exploited catalog were flagged as used by ransomware gangs.
- [15]
CVE-2026-102255 is the fifth SMA1000 CVE attackers have targeted since July, across three separate rounds.
- [16]
Attackers are exploiting a maximum-severity vulnerability in SonicWall SMA1000 appliances, CVE-2026-102255, which was patched on Tuesday, three days before BleepingComputer's Friday report.
ReportedContestedSource: BleepingComputer2 sources— create a free account to open themView cited source
Sources
1 independent publisher whose own reporting we read for this story.
- bleepingcomputer.comMax severity SonicWall SMA1000 flaw now exploited in attacks
1 article · October 9, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- VPN Appliance SecurityFollow
- Server-Side Request ForgeryFollow
- Known Exploited Vulnerabilities catalogFollow