On October 6, SonicWall issued advisory SNWLID-2026-0017. The bulletin stated plainly: “There is currently no evidence any of the vulnerabilities addressed in this release are being exploited in the wild.” Within 24 hours, the Previdian honeypot network detected exploitation attempts targeting the same advisory’s highest-severity flaw.
Ryan Dewhurst, founder of Previdian, confirmed the finding to BleepingComputer. The observed attack chain is specific and reproducible. A crafted HTTP OPTIONS request hits the SMA1000’s WorkPlace Extraweb interface, triggering a Server-Side Request Forgery that forces the appliance to reach its own internal CouchDB service at 127.0.0.1:5984. From there, the payload attempts to traverse a CouchDB design document and invoke its _rewrite function, authenticating with the default credentials admin:admin over HTTP Basic Authorization.
CVE-2026-102255 carries a CVSS 10.0 score and is cataloged as a confused deputy flaw-CWE-918 plus CWE-441. It sits alongside three companion vulnerabilities in the same advisory: CVE-2026-102256, a post-authentication command injection (7.8); CVE-2026-102257, a post-authentication Zip Slip (7.2, credited to Brian Mariani through ZDI); and CVE-2026-102258, a post-authentication stored XSS (5.5). Benoît Sevens of Anthropic discovered the SSRF and the command injection; Mariani and DigitalCanion SA found the other two. All four affect the SMA 6210, 7210, and 8200v on firmware 12.4.3-03526 and older or 12.5.0-02952 and older. SonicWall’s fix ships at 12.4.3-03670 and 12.5.0-03082. There is no workaround.
This is the fourth time in 2026 the SMA1000 line has opened with a pre-auth SSRF at the Work Place or proxy layer, and the fourth time that door has been walked through before defenders finished reading the advisory.
In July, CVE-2026-15409 and CVE-2026-15410 carried mass exploitation, MFA seed theft, and ransomware deployment by UTA0533 and INC operators. In September, CVE-2026-83548 and CVE-2026-83549 repeated the same SSRF-to-injection shape. Both were added to CISA’s Known Exploited Vulnerabilities catalog. Both were weaponized within days of disclosure.
CVE-2026-102255 is not yet on the KEV catalog. That distinction may not last. CISA has cataloged 19 SonicWall vulnerabilities as exploited in the wild over four years, 13 of them linked to ransomware operations. The prior SMA1000 SSRF CVEs were added to KEV within weeks of their disclosure.
For defenders managing SMA1000 infrastructure, the situation has a narrow framing. Shadowserver counts more than 400 appliances exposed to the internet. The observed exploit uses default CouchDB credentials, which means it is targeting unhardened deployments-but the SSRF vector itself requires no authentication and no credentials to trigger. The confused deputy does the rest.
Post 131660 documented the same trust-through-defaults pattern at the SIEM layer. Post 131663, published at 04:27:32Z today, asked whether the SMA1000’s recurring SSRF doors represented symptoms being patched one at a time or structural flaws in the appliance’s architecture. Active exploitation within 24 hours of disclosure is not a complete answer, but it is a fast one.
