A Critical Flaw in SonicWall’s Secure Remote Access Gateways is Being Exploited in the Wild
Security researchers have discovered that attackers are actively exploiting a critical vulnerability in SonicWall’s secure remote access gateways, specifically the SMA1000 appliances. This flaw, tracked as CVE-2026-102255, was patched by SonicWall just three days ago, but it appears that malicious actors have already started to take advantage of it.
The vulnerability affects the Appliance WorkPlace interface on certain SMA1000 models, including the 6210, 7210, and 8200v. However, it’s worth noting that this issue does not impact the SMA 100 Series product line or SSL-VPN running on SonicWall firewalls. To exploit the flaw, attackers can use a crafted OPTIONS request to reach the appliance’s internal CouchDB service, which allows them to traverse into sensitive areas of the system and perform unauthorized operations.
Previdian founder and security researcher Ryan Dewhurst told BleepingComputer that his company’s honeypot network has detected exploitation attempts consistent with the CVE-2026-102255 flaw. “The requests targeted the WorkPlace Extraweb interface, using a crafted OPTIONS request to reach the appliance’s internal CouchDB service at 127.0.0.1:5984,” Dewhurst explained. “The payload attempted to traverse into a CouchDB design document and invoke its _rewrite function, while supplying an HTTP Basic Authorization header containing the credentials admin:admin.”
This vulnerability is particularly concerning because it affects the same WorkPlace interface targeted by earlier SSRF (Server-Side Request Forgery) vulnerabilities disclosed in July and September 2026. However, the October vulnerability uses a different exploitation technique, which could potentially make it more challenging for defenders to detect.
What’s even more alarming is that SonicWall’s SMA1000 appliances are often targeted because they’re used by Managed Service Providers (MSSPs), large corporations, and government agencies for secure remote access to internal applications and corporate networks. As a result, it’s essential for these organizations to ensure their devices are properly patched and secured.
In the past four years, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added 19 SonicWall vulnerabilities to its catalog of actively exploited flaws, flagging 13 of them as used by ransomware gangs. This highlights the importance of addressing security issues promptly and consistently updating software and systems to prevent exploitation.
In light of this incident, it’s crucial for organizations using SonicWall SMA1000 appliances to take immediate action to protect themselves from potential attacks. First and foremost, they should verify that their devices are running the latest patches and firmware versions. Additionally, they should review their system configurations and ensure that all sensitive areas are properly secured.
To stay ahead of these threats, it’s also essential for organizations to maintain a robust security posture, including regular vulnerability assessments, penetration testing, and incident response planning. By taking proactive measures, organizations can minimize the risk of being compromised by these types of attacks.
Source: Bleeping Computer — 2026-10-09