Critical SonicWall SMA1000 Vulnerability Exploited in Cyber Attacks

www.news4hackers.com-critical-sonicwall-sma1000-vulnerability-exploited-in-cyber-attacks-critical-sonicwall-sma1000-vulnerability-exploited-in-cyber-attacks

Threat actors have begun leveraging a critical vulnerability in SonicWall SMA1000 appliances (CVE-2026-102255) that received a patch three days prior.

Vulnerability Details

The flaw impacts the Appliance WorkPlace interface on SMA1000 6210, 7210, and 8200v models but does not affect the SMA 100 Series product line or SSL-VPN functionality on SonicWall firewalls.

Exploitation Method

Exploitation involves manipulating the WorkPlace interface to enable a remote attacker to execute unauthorized actions by directing the appliance to initiate requests on their behalf.

Researcher Findings

Security researcher Ryan Dewhurst of Previdian reported detecting malicious activity aligning with CVE-2026-102255. His analysis revealed attempts targeting the WorkPlace Extraweb interface through crafted OPTIONS requests. These requests aimed to access the appliance’s internal CouchDB service at 127.0.0.1:5984, with payloads attempting to traverse to a CouchDB design document and trigger its _rewrite function.

The attacks included HTTP Basic Authorization headers containing the default credentials admin:admin.

Context and Previous Incidents

This vulnerability differs from earlier SSRF flaws affecting the same interface in July and September 2026, as it employs a distinct exploitation method. Dewhurst noted that while the activity suggests active exploitation, no conclusive evidence of successful compromises has been confirmed.

Shadowserver Data

Shadowserver, an internet threat monitoring organization, has identified over 400 SMA1000 appliances exposed online, though it remains unclear how many are honeypots or have applied the latest patch.

Historical Attacks

In July, threat actors exploited two zero-day vulnerabilities (CVE-2026-15409 and CVE-2026-15410) to deploy malware such as Sou5, OrangeTail, and RootRun on compromised VPN devices. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) later linked these incidents to ransomware groups.

Recent Exploitation Trends

Recent reports indicate that attackers are combining two newly disclosed zero-days (CVE-2026-83548 and CVE-2026-83549) to execute remote code on vulnerable SMA1000 gateways.

CISA Observations

Over the past four years, CISA has documented 19 SonicWall vulnerabilities as actively exploited, with 13 tied to ransomware operations.

Technical and Mitigation Insights

Technical details of the latest flaw highlight the ongoing risks associated with misconfigured or unpatched systems. Organizations utilizing SMA1000 appliances are advised to apply the available patches immediately and review network configurations to mitigate potential exposure.

Security Recommendations

The recurrence of SSRF-based attacks on the WorkPlace interface underscores the importance of continuous monitoring and proactive security measures for critical infrastructure.


Blog Image

About Author

en_USEnglish