Trusence Every claim has a source
Last updated 9 October 2026 Search Türkçe
← All stories
Security

Exploits are now targeting SonicWall’s patched SMA1000 flaw

More than 400 SMA1000 appliances are visible online, leaving exposed systems under active attack attempts.

SonicWall’s patched maximum-severity flaw in SMA1000 appliances is now being used in attack attempts, according to reports from a honeypot network. The bug, CVE-2026-102255, affects the Appliance WorkPlace interface on SMA1000 6210, 7210, and 8200v devices, while SonicWall says it does not affect SMA 100 Series products or SSL-VPN on its firewalls. Ryan Dewhurst of Previdian said the observed traffic targeted the WorkPlace Extraweb interface with a crafted OPTIONS request aimed at the appliance’s internal CouchDB service, and that the evidence matches exploitation attempts but not confirmed compromises. Shadowserver says more than 400 SMA1000 appliances are visible on the internet, which is relevant because these gateways are widely used for VPN access by MSPs, large enterprises, and government agencies.

Why it matters

For organisations running SMA1000 appliances, patching is no longer only preventive: the flaw is already being used in attack attempts. SonicWall says its SMA 100 Series and firewall SSL-VPN are not affected, which narrows the urgent exposure to SMA1000 systems that remain online and reachable.

Sources

  • BleepingComputer