Attackers are now exploiting a CVSS 10.0 server-side request forgery (SSRF) flaw in SonicWall’s SMA1000 Appliance Work Place.
In its advisory on Tuesday, SonicWall did not say if the bug was actively exploited, but security researchers at Previdian said that the company’s honeypots had detected exploitation.
As of Friday, CVE-2026-102255 was not yet added to the known exploited vulnerabilities list by the Cybersecurity and Infrastructure Security Agency (CISA), but security pros said that heading into the weekend, teams should not wait.
Shane Barney, chief information security officer at Keeper Security, said that maximum-severity flaws in edge infrastructure are precisely what threat actors look for heading into a weekend. Barney said SSRF vulnerabilities in edge appliances bypass the perimeter entirely, giving attackers direct access to internal systems.
“With honeypots already detecting exploitation activity and hundreds of appliances exposed online, security teams cannot afford to take a ‘wait and see’ approach for CISA to formally add this to the KEV catalog,” said Barney. “Edge devices represent the initial line of defense, and when they are compromised, attackers gain an immediate foothold without needing complex malware.”
Heading into the weekend, Barney said security teams running affected SonicWall SMA1000 models (6210, 7210, and 8200v) should apply the vendor hotfixes immediately rather than relying on workarounds. If teams can’t patch before the weekend, isolate the Appliance Work Place interface from public internet access. Barney said teams should also review logs originating from these appliances for anomalous outbound or internal requests, as SSRF exploits typically serve as the initial vector for lateral movement, credential harvesting and secondary access attempts.
Jason Soroko, senior fellow at Sectigo, said this flaw can let an attacker reach internal appliance functions without logging in. Multifactor authentication therefore does not close this route: the appliance that controls remote access can itself become the entry point.
Soroko pointed out that researchers said they observed exploitation attempts consistent with the flaw, but have not confirmed that those attempts succeeded.
“That distinction matters for reporting, but security teams already have enough evidence to act,” said Soroko. “Waiting for a CISA catalog entry would leave affected systems exposed while attackers are testing them.”
Before the weekend, Soroko said teams should identify affected SMA1000 appliances, install SonicWall’s update and verify that each device is running the fixed software. If teams can’t patch an appliance today, Soroko said take it off the internet until it can: preserve and review logs for suspicious requests, configuration changes and unexpected connections.
“Patching closes the vulnerability, but does not establish whether an attacker already gained access,” said Soroko. “Evidence of compromise should trigger isolation and incident response. Assign someone to monitor alerts through the weekend, with authority to disconnect an appliance if needed.”
Denis Calderone, chief technology officer at Suzu Labs, added that this case represents the third CVSS 10.0 pre-authentication SSRF in Work Place interface in nine months: July, September, and now October.
Calderone said each one lets an unauthenticated attacker trick the appliance into proxying requests to internal services that were never supposed to be externally reachable. The observed exploitation attempts are targeting the internal CouchDB service on localhost, and Calderone said there’s already a public Metasploit module from the September chain showing exactly how to turn CouchDB access into root-level code execution on these appliances: the internal architecture has not changed.
“The firmware SonicWall released in September to fix the last chain is exactly what’s vulnerable to this one,” said Calderone. “Every SMA1000 that was patched after September is exposed again. There’s no workaround. SonicWall has not published indicators of compromise for this vulnerability, and unlike the July advisory where they gave defenders specific log patterns to hunt for, the October advisory is just ‘patch.’ That’s not enough when exploitation attempts are already in the wild three days post-disclosure.”
Calderone advised teams to patch 12.4.3-03670 or 12.5.0-03082 before the weekend: the appliance reboots during installation and drops all VPN sessions, so plan a short maintenance window and do not apply the hotfix over VPN.
Before patching, Calderone said export the configuration and have console access ready. After patching, hunt using the IOC patterns from the July chain since the internal architecture is the same:
- Check /var/lib/unit/conf.json for unexpected routes.
- Review extraweb_access.log for HTTP 200 responses to /api/login or /api/logout.
- Look at ctrl-service.log for path traversal entries.
- Watch for authentication attempts originating from the appliance's own IP against the company’s domain controllers.
“If anything looks off, re-image the appliance before deploying the new firmware,” said Calderone. “Patching a compromised box just gives you a patched compromised box.”