Max-severity SonicWall SMA1000 SSRF flaw now exploited in the wild
TLDR
- Attackers are exploiting CVE-2026-102255, a maximum-severity (CVSS 10.0) server-side request forgery flaw in SonicWall SMA1000 appliances, just three days after SonicWall patched it.1
- The bug hits the Appliance WorkPlace interface on SMA1000 6210, 7210 and 8200v models, letting an unauthenticated remote attacker direct the appliance to issue internal requests on their behalf; it does not affect the SMA 100 Series or firewall SSL-VPN.1
- Security researcher Ryan Dewhurst told BleepingComputer his honeypot network detected exploitation attempts reaching the appliance's internal CouchDB service, consistent with the flaw, though it is not yet confirmed whether any attempts succeeded.1
- It is the third CVSS 10.0 pre-authentication SSRF disclosed in the WorkPlace interface in nine months, following prior zero-days in July and September; CISA linked some of the July exploitation to ransomware gangs.12
SonicWall patched CVE-2026-102255 on Tuesday without flagging it as actively exploited, but by Friday Previdian founder Ryan Dewhurst said the company's honeypots had already detected exploitation attempts.1 "The requests targeted the WorkPlace Extraweb interface, using a crafted OPTIONS request to reach the appliance's internal CouchDB service at 127.0.0.1:5984. The payload attempted to traverse into a CouchDB design document and invoke its _rewrite function, while supplying an HTTP Basic Authorization header containing the credentials admin:admin," Dewhurst told BleepingComputer.1 He said the technique differs from the SSRF vulnerabilities disclosed in July and September but targets the same WorkPlace interface, and that Previdian has not yet established whether any attempts succeeded in compromising a system.1
SonicWall described the flaw as letting "a remote unauthenticated attacker potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations."1 Shadowserver currently tracks more than 400 SMA1000 appliances exposed online, though it is unclear how many are honeypots or already patched.1 As of Friday, CVE-2026-102255 had not been added to CISA's Known Exploited Vulnerabilities catalog, but security professionals quoted by SC Media said teams should not wait for that listing before acting.2
Denis Calderone, chief technology officer at Suzu Labs, noted this is the third CVSS 10.0 pre-authentication SSRF in the WorkPlace interface in nine months, after flaws in July and September, and said each lets an unauthenticated attacker proxy requests to internal services never meant to be externally reachable; he pointed out there is already a public Metasploit module from the September chain demonstrating how to turn CouchDB access into root-level code execution.2 SMA1000 gateways are frequently targeted because MSSPs, large corporations and government agencies rely on them for VPN access into internal networks; CISA has added 19 SonicWall vulnerabilities to its KEV catalog over the past four years, 13 of them flagged as used by ransomware gangs.1 Keeper Security CISO Shane Barney said teams running affected SMA1000 models should apply SonicWall's hotfix immediately rather than relying on workarounds, or isolate the WorkPlace interface from the public internet if they cannot patch before the weekend.2
Why it matters: a maximum-severity, pre-authentication flaw in the same interface hit by two prior CVSS 10.0 SSRF bugs this year, already showing exploitation attempts within three days of patching and ahead of a weekend when security teams are thinnest, is exactly the scenario CISA's past SonicWall-to-ransomware pipeline warns about.