SonicWall patched a maximum-severity server-side request forgery in SMA1000 appliances on 6 October 2026. On 9 October, Previdian told BleepingComputer its honeypots had seen requests consistent with CVE-2026-102255. SonicWall has not yet marked the flaw as exploited in its advisory. Previdian has not confirmed a successful compromise.
What happened
The flaw sits in the Appliance WorkPlace interface on SMA1000 models 6210, 7210 and 8200v. It does not affect the SMA 100 Series or SSL-VPN on SonicWall firewalls. An unauthenticated remote attacker can make the appliance issue requests on their behalf and reach internal functions.
Previdian described crafted OPTIONS requests to the WorkPlace Extraweb interface that tried to reach an internal CouchDB service at 127.0.0.1:5984, traverse into a design document, call its rewrite function, and send an HTTP Basic header of admin:admin. Shadowserver tracks more than 400 SMA1000 appliances exposed online. That count mixes honeypots and already-patched hosts.
Who is affected
Anyone still running an unpatched SMA1000 6210, 7210 or 8200v with the WorkPlace interface reachable. Managed service providers, large firms and government sites use these gateways for remote access, which is why earlier SMA1000 zero-days drew ransomware operators.
- SMA1000 6210, 7210 and 8200v with WorkPlace exposed
- Not the SMA 100 Series, and not firewall SSL-VPN
- Prior SMA1000 flaws in 2026 were already used for malware and, in some cases, ransomware
What to do now
Install the 6 October firmware for SNWLID-2026-0017 and confirm the build, not just that an update job ran. Hunt WorkPlace Extraweb logs for OPTIONS requests aimed at 127.0.0.1:5984 or CouchDB rewrite paths. If those appear, treat the appliance as suspect: isolate it, rotate credentials that passed through it, and rebuild rather than hoping a patch cleans a foothold.
Source: BleepingComputer, Max severity SonicWall SMA1000 flaw now exploited in attacks.
Also on the blog
- CVE-2026-107406: NetScaler SAML RCE at CVSS 9.5
- Five Flax Typhoon Flaws, CISA Deadline 11 October
- CVE-2026-21589: unauthenticated file read on 8 Atlassian products
- Germany Arrests Alleged Qilin Ransomware Leader
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.