DKDKCISSPSearch
VulnerabilitiesDEVELOPING

SonicWall SSRF bug rated 10.0 exploited in SMA1000 Appliance Work Place

Attackers are now exploiting a CVSS 10.0 server-side request forgery (SSRF) flaw in SonicWall’s SMA1000 Appliance Work Place.

DKCISSP News DeskSC Media10 Oct 2026, 12:43 am
SonicWall SSRF bug rated 10.0 exploited in SMA1000 Appliance Work Place
Image courtesy of SC Media. Original report
DKCISSP REPORT

Attackers are now exploiting a CVSS 10.0 server-side request forgery (SSRF) flaw in SonicWall’s SMA1000 Appliance Work Place.

In its advisory on Tuesday, SonicWall did not say if the bug was actively exploited, but security researchers at Previdian said that the company’s honeypots had detected exploitation.

As of Friday, CVE-2026-102255 was not yet added to the known exploited vulnerabilities list by the Cybersecurity and Infrastructure Security Agency (CISA), but security pros said that heading into the weekend, teams should not wait.

While SonicWall has not yet flagged this vulnerability as actively exploited in its Tuesday advisory, Previdian founder and security researcher Ryan Dewhurst told BleepingComputer on Friday that the company's honeypot network has detected exploitation attempts consistent with the CVE-2026-102255 flaw.

Tracked as CVE-2026-102255 , the flaw affects the Appliance WorkPlace interface on SMA1000 6210, 7210, and 8200v models, but does not affect the SMA 100 Series product line or SSL-VPN running on SonicWall firewalls.

Heading into the weekend, Barney said security teams running affected SonicWall SMA1000 models (6210, 7210, and 8200v) should apply the vendor hotfixes immediately rather than relying on workarounds.

If teams can’t patch before the weekend, isolate the Appliance Work Place interface from public internet access.

Jason Soroko, senior fellow at Sectigo, said this flaw can let an attacker reach internal appliance functions without logging in.

SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now

Soroko pointed out that researchers said they observed exploitation attempts consistent with the flaw, but have not confirmed that those attempts succeeded.

What happened

Attackers are now exploiting a CVSS 10.0 server-side request forgery (SSRF) flaw in SonicWall’s SMA1000 Appliance Work Place.

In its advisory on Tuesday, SonicWall did not say if the bug was actively exploited, but security researchers at Previdian said that the company’s honeypots had detected exploitation.

What changed

As of Friday, CVE-2026-102255 was not yet added to the known exploited vulnerabilities list by the Cybersecurity and Infrastructure Security Agency (CISA), but security pros said that heading into the weekend, teams should not wait.

While SonicWall has not yet flagged this vulnerability as actively exploited in its Tuesday advisory, Previdian founder and security researcher Ryan Dewhurst told BleepingComputer on Friday that the company's honeypot network has detected exploitation attempts consistent with the CVE-2026-102255 flaw.

Who is affected

Tracked as CVE-2026-102255 , the flaw affects the Appliance WorkPlace interface on SMA1000 6210, 7210, and 8200v models, but does not affect the SMA 100 Series product line or SSL-VPN running on SonicWall firewalls.

Heading into the weekend, Barney said security teams running affected SonicWall SMA1000 models (6210, 7210, and 8200v) should apply the vendor hotfixes immediately rather than relying on workarounds.

Why it matters

If teams can’t patch before the weekend, isolate the Appliance Work Place interface from public internet access.

Jason Soroko, senior fellow at Sectigo, said this flaw can let an attacker reach internal appliance functions without logging in.

Technical details

SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now

Soroko pointed out that researchers said they observed exploitation attempts consistent with the flaw, but have not confirmed that those attempts succeeded.

Over the last four years, CISA has added 19 SonicWall vulnerabilities to its catalog of actively exploited flaws , flagging 13 of them as used by ransomware gangs.

Response

Before the weekend, Soroko said teams should identify affected SMA1000 appliances, install SonicWall’s update and verify that each device is running the fixed software.

Attackers are exploiting a maximum-severity vulnerability in SonicWall SMA1000 appliances (CVE-2026-102255) that was patched on Tuesday, three days ago.

What security teams should do

Dewhurst also added that while this activity is consistent with active exploitation attempts, Previdian has not yet established "whether those attempts would have successfully compromised any systems." While Internet threat watchdog Shadowserver now tracks more than 400 SMA1000 appliances exposed online, there is no information on how many are honeypots or have already been patched against CVE-2026-102255 attacks.

If teams can’t patch an appliance today, Soroko said take it off the internet until it can: preserve and review logs for suspicious requests, configuration changes and unexpected connections.

What remains unknown

In its advisory on Tuesday, SonicWall did not say if the bug was actively exploited, but security researchers at Previdian said that the company’s honeypots had detected exploitation.

Dewhurst also added that while this activity is consistent with active exploitation attempts, Previdian has not yet established "whether those attempts would have successfully compromised any systems." While Internet threat watchdog Shadowserver now tracks more than 400 SMA1000 appliances exposed online, there is no information on how many are honeypots or have already been patched against CVE-2026-102255 attacks.

Attribution

SC Media: Attackers are now exploiting a CVSS 10.0 server-side request forgery (SSRF) flaw in SonicWall’s SMA1000 Appliance Work Place.

BleepingComputer: Attackers are exploiting a maximum-severity vulnerability in SonicWall SMA1000 appliances (CVE-2026-102255) that was patched on Tuesday, three days ago.

What to watch next

Watch for new exploitation reports and updated indicators of compromise.

Watch for updated vendor guidance and fixed-version details.

MORE IN VULNERABILITIES

More cybersecurity reporting

Unpatched AhsayCBS flaws exploited to deploy webshells, mine cryptoBleepingComputer · 9 Oct 2026, 10:47 pmAtlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public DetailsThe Hacker News · 7 Oct 2026, 5:19 pmAtlassian warns of critical file-access flaw in Jira, ConfluenceBleepingComputer · 6 Oct 2026, 11:04 pmRed Hat’s Lightwell Project Remediates 400 Open-Source VulnerabilitiesInfosecurity Magazine · 6 Oct 2026, 6:31 pm