Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Here’s a look at the Nobel Prizes for science

    October 9, 2026

    For Indian communities, fishmeal factories bring pollution, danger and protests

    October 9, 2026

    Shell to take a slice of Equinor’s $10 billion oil project in Canada

    October 9, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Here’s a look at the Nobel Prizes for science
    • For Indian communities, fishmeal factories bring pollution, danger and protests
    • Shell to take a slice of Equinor’s $10 billion oil project in Canada
    • Inspecting claim USPS is installing surveillance cameras on delivery trucks
    • UN says Pentagon plan to livestream execution of Fort Hood shooter would amount to torture – US politics live | Fort Hood shootings
    • Robert Jenrick launches scathing broadside against ‘Kensington Kemi’ | Politics
    • Dunking on Dating App Profiles Is Content Gold. People Are Getting Sick of It
    • Max severity SonicWall SMA1000 flaw now exploited in attacks
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, October 9
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Max severity SonicWall SMA1000 flaw now exploited in attacks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 9, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Attackers are exploiting a maximum-severity vulnerability in SonicWall SMA1000 appliances (CVE-2026-102255) that was patched on Tuesday, three days ago.

    Tracked as CVE-2026-102255, the flaw affects the Appliance WorkPlace interface on SMA1000 6210, 7210, and 8200v models, but does not affect the SMA 100 Series product line or SSL-VPN running on SonicWall firewalls.

    “By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations,” SonicWall explained.

    While SonicWall has not yet flagged this vulnerability as actively exploited in its Tuesday advisory, Previdian founder and security researcher Ryan Dewhurst told BleepingComputer on Friday that the company’s honeypot network has detected exploitation attempts consistent with the CVE-2026-102255 flaw.

    “The requests targeted the WorkPlace Extraweb interface, using a crafted OPTIONS request to reach the appliance’s internal CouchDB service at 127.0.0.1:5984. The payload attempted to traverse into a CouchDB design document and invoke its _rewrite function, while supplying an HTTP Basic Authorization header containing the credentials admin:admin,” Dewhurst told BleepingComputer.

    “It affects the same WorkPlace interface targeted by earlier SSRF vulnerabilities disclosed in July and September 2026. However, the October vulnerability uses a different exploitation technique.

    Dewhurst also added that while this activity is consistent with active exploitation attempts, Previdian has not yet established “whether those attempts would have successfully compromised any systems.”

    While Internet threat watchdog Shadowserver now tracks more than 400 SMA1000 appliances exposed online, there is no information on how many are honeypots or have already been patched against CVE-2026-102255 attacks.

    SMA1000 instances exposed online
    SMA1000 instances exposed online (Shadowserver)

    ​SMA1000 enterprise-grade secure remote access gateways are often targeted because Managed Service Providers (MSSPs), many large corporations, and government agencies use them for VPN access to internal apps and corporate networks.

    For instance, in July, threat actors abused two SMA1000 zero-days (CVE-2026-15409 and CVE-2026-15410) for weeks to install custom Sou5, OrangeTail, and RootRun malware on vulnerable VPN appliances.

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) later linked some of these attacks to ransomware gangs.

    Last month, SonicWall also warned customers that attackers were chaining two new zero-days (CVE-2026-83548 and CVE-2026-83549) in the wild to execute remote code on vulnerable SMA1000 gateways.

    Over the last four years, CISA has added 19 SonicWall vulnerabilities to its catalog of actively exploited flaws, flagging 13 of them as used by ransomware gangs.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    attacks Exploited Flaw Max severity SMA1000 SonicWall
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    In Other News: AI Used in Korean Bank Breaches, Poem-Guided Botnet, Empire Admin Gets 40 Years

    Man admits to running network of 15,000 money mules for cybercriminals

    Microsoft: Outdated Windows devices will stop receiving security updates

    FBI Seizes 7 Domains, Disrupts Flax Typhoon Tools Used in Critical Infrastructure Intrusions

    Anthropic Fast-Tracks AI Bug Reports to OSS Maintainers, Taps 11 Firms for OT Security

    Citrix Urges Immediate Patching of Critical NetScaler Vulnerability

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Here’s a look at the Nobel Prizes for science

    October 9, 2026

    For Indian communities, fishmeal factories bring pollution, danger and protests

    October 9, 2026

    Shell to take a slice of Equinor’s $10 billion oil project in Canada

    October 9, 2026

    Inspecting claim USPS is installing surveillance cameras on delivery trucks

    October 9, 2026
    Latest Posts

    Reform donor Arron Banks urged to set out extent of surveillance of journalists | Arron Banks

    August 10, 2026

    The Canadian Secessionists Who Love Trump

    August 10, 2026

    How ‘Harry Potter’ Fans Protected Dobby’s Grave From the Path of a U.K.-Ireland Power Line

    August 10, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Here’s a look at the Nobel Prizes for science

    October 9, 2026

    For Indian communities, fishmeal factories bring pollution, danger and protests

    October 9, 2026

    Shell to take a slice of Equinor’s $10 billion oil project in Canada

    October 9, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.