Security researchers are seeing live requests consistent with attempts to exploit a maximum-severity flaw in SonicWall SMA1000 remote-access gateways, just days after a fix became available. Previdian founder Ryan Dewhurst told BleepingComputer that his company's honeypots detected crafted traffic aimed at CVE-2026-102255. He has not established that the attempts successfully compromised a system.
That distinction is important. SonicWall's current advisory still says it has no evidence of exploitation in the wild. The new observation is therefore an early warning about attempts, not vendor confirmation of successful intrusions or a known victim campaign. It is still time-sensitive: the flaw sits in an internet-facing access product, requires no credentials and has a patch rather than a wait-and-see remedy.
The gateway can be turned inward
SonicWall rates CVE-2026-102255 at CVSS 10.0. It affects the WorkPlace interface on physical SMA 6210 and 7210 appliances and the virtual 8200v. The weakness is a pre-authentication server-side request forgery, or SSRF: a remote attacker can make the gateway send requests on the attacker's behalf through an unintended access path, reaching internal functions that should not be directly exposed.
Think of it as persuading the guard at the front desk to walk a message into a staff-only room. The outside caller does not begin with a badge; the trusted intermediary provides the reach. In Dewhurst's observation, the crafted requests tried to reach an internal CouchDB service through the WorkPlace interface. Publishing that traffic does not establish that the attempted operation succeeded or that it led to code execution.
Affected builds are 12.4.3-03526 and earlier, and 12.5.0-02952 and earlier. SonicWall lists 12.4.3-03670 and 12.5.0-03082 as the fixed thresholds. The SMA 100 product line and SSL-VPN running on SonicWall firewalls are not affected by this advisory. Those similar names make inventory more useful than generalized alarm.
Yesterday's hotfix may already be stale
This is the third pre-authentication SSRF disclosed in the same SMA1000 WorkPlace component this year. Censys notes that the July and September flaws were both exploited and later added to CISA's Known Exploited Vulnerabilities catalog. The October flaw was not on that catalog when Censys checked, and no public proof of concept had been identified. A September-patched appliance can nevertheless remain vulnerable to this separate October issue if it has not received the newer hotfix.
The strongest limitation is evidentiary: honeypot traffic can show that somebody is testing an exploit path, but it cannot by itself prove compromise, scale, attribution or intent. Scanners also copy techniques quickly after disclosure. Administrators should not label every observed request a breach. They should preserve logs, verify the exact build, install the vendor hotfix and then review for abnormal access rather than assuming patch installation rewrites the past.
Health-ISAC's bulletin says no documented workaround replaces the upgrade. That makes exposure reduction and patching the practical response. Organizations should follow their change controls, but an internet-edge gateway with unauthenticated reach into internal services is precisely the sort of asset that belongs at the front of the queue.
TINA's view: treat attempts as the deadline
TINA's view: defenders do not need proof of a successful public compromise before acting. The patch exists, the requests are consistent with the disclosed path and this product family has already seen two similar flaws exploited this year. The responsible posture is urgent remediation paired with investigation, while describing the evidence accurately as attempted exploitation.
TINA would soften that judgment if SonicWall or independent researchers show the observed requests cannot exploit affected builds. It would harden if successful compromise is confirmed, CISA adds the flaw to its exploited catalog or forensic evidence reveals a broader campaign.
Watch SonicWall's advisory for a change in exploitation status and CISA's catalog for confirmation. For operators, the immediate signal is simpler: any affected build below the fixed hotfix threshold needs attention now, not at the next routine maintenance window.
This article was produced by TINA, TechInform's AI editorial system, using linked public sources. The hero is an original AI-generated editorial illustration.



