One distinction matters before the panic sets in. Attackers sending exploit requests is not the same as attackers taking over appliances. The researcher has not confirmed that any of these attempts worked, and SonicWall had not marked the flaw as exploited when it published its advisory. Given this product line's recent history, that's a thin comfort.
What the honeypots saw
BleepingComputer reported the activity on October 9. Previdian founder and security researcher Ryan Dewhurst told BleepingComputer on Friday that the company's honeypot network has detected exploitation attempts consistent with the CVE-2026-102255 flaw.
Dewhurst gave a fairly specific description of the traffic:
- The requests went to the SMA1000's WorkPlace Extraweb interface.
- They used a crafted HTTP
OPTIONSrequest to reach the appliance's internal CouchDB service on127.0.0.1:5984. That port should only be reachable from inside the box. - The payload tried to traverse into a CouchDB design document and call its
_rewritefunction. - The request carried an HTTP Basic Authorization header with the credentials
admin:admin.
He added that the October flaw "affects the same WorkPlace interface targeted by earlier SSRF vulnerabilities disclosed in July and September 2026. However, the October vulnerability uses a different exploitation technique." That comparison is his own assessment. SonicWall has not published a technical description of the exploit.
He was also careful about what the data shows. While this activity is consistent with active exploitation attempts, Previdian has not yet established "whether those attempts would have successfully compromised any systems." So "attempts seen on honeypots" is accurate. "Appliances being compromised" is not established yet.
Section summary: Someone is sending SSRF requests aimed at the appliance's internal CouchDB. Nobody has publicly confirmed a successful break-in through this CVE.
The vulnerability, briefly
SonicWall disclosed the flaw in advisory SNWLID-2026-0017 on October 6. Field Effect said the vendor describes the flaw as an unintended alternate access path that allows a remote, unauthenticated attacker to make the appliance issue requests on their behalf. SonicWall scores it CVSS 10.0, and the October 7 BleepingComputer report said it can be exploited by remote attackers without privileges in low-complexity attacks.
The scope is narrow, which makes it easy to check whether you're affected:
- Affected: the Appliance WorkPlace interface on SMA1000 6210, 7210, and 8200v models, including both physical and virtual appliances.
- Not affected: the SMA 100 Series product line or SSL-VPN running on SonicWall firewalls.
The same advisory fixes three other bugs, all of which require a login. According to The Hacker News, they are:
- CVE-2026-102256: OS command injection that needs an administrator login (CVSS 7.8).
- CVE-2026-102257: a Zip Slip path traversal in the Appliance Management Console (CVSS 7.2).
- CVE-2026-102258: stored cross-site scripting in the AMC (CVSS 5.5).
The honeypot activity involves only CVE-2026-102255. Nothing reported so far links the other three to these requests.
The version trap: "patched in September" isn't patched anymore
This is the most useful practical point, and it's easy to miss. The newest vulnerable builds are the same builds SonicWall shipped in September to fix the previous zero-days. As security firm Rescana put it, the newest affected builds are exactly the builds that fixed the September zero-days: 12.4.3-03526 and 12.5.0-02952. An appliance that was fully patched for September is vulnerable today.
| Branch | Vulnerable | Fixed |
|---|---|---|
| 12.4.3 | 12.4.3-03526 and earlier | 12.4.3-03670 and later |
| 12.5.0 | 12.5.0-02952 and earlier | 12.5.0-03082 and later |
SonicWall lists no workaround. The Hacker News reports that the hotfix is available from the MySonicWall portal and that the appliance restarts when installation finishes.
If your change-management records show "SMA1000 – remediated" from early September, that entry is now out of date.
What admins should do now
The steps below come from the vendor guidance and analyst reporting covered here:
- Inventory every SMA1000. That includes 6210 and 7210 hardware and virtual 8200v instances. The Cloud Security Alliance (CSA) also suggests checking appliances managed through a central management server.
- Check the exact build number. Compare it against the table above. Being on a recent build is not the same as being on a fixed one.
- Install the applicable hotfix from MySonicWall. The appliance reboots, so expect a short VPN outage and warn users first.
- Restrict WorkPlace exposure where the business allows it. CSA notes that limiting the portal to required source networks shrinks the pool of potential attackers. It does not replace patching.
- Keep the AMC off the internet. CSA recommends confirming that the management console sits on a management segment that user-facing interfaces and the internet can't reach.
- Don't assume a clean history. CSA says patching alone does not fix an appliance that was compromised before the patch. If you find indicators of compromise, it recommends redeploying from a clean image, rotating administrator and user credentials, and reissuing TOTP seeds. That follows what SonicWall told customers after the July and September incidents. The Hacker News notes that SonicWall has not issued the same instruction for the October flaws.
No vendor-published detection rule for this activity has been confirmed. Watching for unexpected OPTIONS requests to WorkPlace, or for anything touching internal CouchDB paths, is a reasonable hunting idea based on Dewhurst's description. Treat it as a lead, not a validated signature.
Why this appliance keeps getting hit
This is the third time this year attackers have gone after the same interface. In July, threat actors abused two SMA1000 zero-days (CVE-2026-15409 and CVE-2026-15410) for weeks to install custom Sou5, OrangeTail, and RootRun malware on vulnerable VPN appliances. Volexity, which helped SonicWall investigate, traced that activity back to June 22. It found that the July SSRF exposed internal services including CouchDB, which the attackers queried before using a command-injection flaw to get root. CISA later tied some of those attacks to ransomware gangs. In September, SonicWall disclosed a second pair of zero-days, CVE-2026-83548 and CVE-2026-83549, which attackers chained to get remote code execution.
Dewhurst said the October requests use a different technique from earlier waves, so it would be speculative to assume this is the same actor. Still, CouchDB shows up in both the July chain and the October honeypot traffic. Attackers clearly know what sits behind WorkPlace.
There's also a structural problem. A CVSS 10.0 pre-auth SSRF in the same component three times in about twelve weeks suggests to analysts at CSA that earlier fixes may have closed individual routes without fixing the underlying request-routing design. CSA labels that as its own inference, not a vendor finding. The Hacker News adds that SonicWall has not said whether the new SSRF can be chained with the October command-injection bug the way earlier SSRFs were.
Keeping the alarm calibrated
A few caveats keep this in proportion:
- The exposure numbers are fuzzy. Shadowserver tracks more than 400 internet-exposed SMA1000 appliances. BleepingComputer notes there's no data on how many are honeypots or already patched.
- Official status hasn't caught up. Rescana checked on the morning of October 9 and reported that CVE-2026-102255 is not in CISA KEV (catalog 2026.10.08, checked 2026-10-09 10:15 IDT). No public proof-of-concept is known. It also noted that CISA's ADP SSVC entry rates it Exploitation "none", Automatable "yes", Technical impact "total". Those ratings came before the honeypot report and may change.
- One honeypot network is one data point. It's credible, specific, and worth acting on, but it doesn't show who is behind the traffic, how widely it's spreading, or whether it works.
In practice, none of these caveats changes the decision. SonicWall's own October 6 position, before anyone reported attack traffic, was to upgrade. With a maximum-severity, unauthenticated, automatable bug in a VPN gateway, now probed in the wild and in a product family attackers have already broken into twice this year, the fix is to install the hotfix now and then check whether anything got in earlier.
Bottom line: if your SMA1000 runs 12.4.3-03526, 12.5.0-02952 or anything older, it is vulnerable to CVE-2026-102255, and that includes appliances fully patched in September. Move to 12.4.3-03670 or 12.5.0-03082 or later, plan for the reboot, and check the appliance for signs of earlier compromise.
References
- Max severity SonicWall SMA1000 flaw now exploited in attacks BleepingComputer · 2026-10-09T08:32:16-04:00
- SonicWall SMA1000 CVE-2026-102255: Third Pre-Auth SSRF of 2026 Makes "Patched in September" Out of Date rescana.com
- SonicWall warns of max severity SSRF flaw in SMA1000 gateways bleepingcomputer.com