Max severity SonicWall SMA1000 flaw now exploited in attacks

A critical vulnerability in SonicWall’s secure remote access gateways has been exploited in real-world attacks just days after a patch was released. The flaw, tracked as CVE-2026-102255, affects specific models of the SMA1000 appliance and allows an attacker to take control of the device without authentication.

The affected devices are the SMA1000 6210, 7210, and 8200v models, which are used by many large corporations and government agencies for VPN access to internal apps and corporate networks. The flaw was first patched on Tuesday, but it appears that attackers have already begun exploiting it in attacks detected by security researchers.

According to Previdian founder Ryan Dewhurst, the vulnerability allows an attacker to direct the appliance to issue requests on their behalf and reach internal functionality, performing unauthorized operations. This can be done using a crafted OPTIONS request to the WorkPlace Extraweb interface, which targets the device’s internal CouchDB service. The payload attempts to traverse into a CouchDB design document and invoke its _rewrite function, while supplying an HTTP Basic Authorization header containing the credentials “admin:admin”.

This is not the first time that SonicWall’s SMA1000 appliances have been targeted by attackers. In July, threat actors exploited two zero-days in the devices to install custom malware on vulnerable VPN appliances. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) later linked some of these attacks to ransomware gangs.

The fact that attackers are already exploiting this new vulnerability just days after it was patched highlights the importance of keeping security up-to-date, even for critical infrastructure devices like secure remote access gateways. With over 400 SMA1000 appliances exposed online and no information on how many have been patched against CVE-2026-102255 attacks, it’s likely that more attacks will be seen in the coming days.

It’s worth noting that this vulnerability is particularly concerning because of its potential impact on enterprise networks. Managed Service Providers (MSSPs), large corporations, and government agencies often use SMA1000 appliances for secure remote access to internal apps and corporate networks. If left unpatched, these devices can provide a backdoor into the network, allowing attackers to move laterally and potentially compromise sensitive data.

As always, it’s essential for organizations that rely on SonicWall’s SMA1000 appliances to ensure they have applied the latest patches and have up-to-date security measures in place. Users should also be vigilant and monitor their systems closely for any signs of suspicious activity. With the rise of ransomware gangs exploiting vulnerabilities in critical infrastructure devices, staying ahead of these attacks requires a proactive approach to cybersecurity.


Source: Bleeping Computer — 2026-10-09