# Researcher detects attack attempts against patched SonicWall SMA1000 flaw

_Published Friday, October 9, 2026 at 9:38 AM EDT · Security · Latest · Tier 2 — Notable_

![Researcher detects attack attempts against patched SonicWall SMA1000 flaw — Primary](https://www.bleepstatic.com/content/hl-images/2026/10/09/SonicWall-headpic.jpg)

Previdian has detected exploitation attempts consistent with CVE-2026-102255, a maximum-severity SonicWall SMA1000 vulnerability patched three days earlier, founder Ryan Dewhurst told BleepingComputer. The flaw affects the Appliance WorkPlace interface on 6210, 7210 and 8200v models, allowing unauthenticated attackers potentially to make the appliance reach internal functions and perform unauthorized operations.

The observed requests targeted an internal CouchDB service through the WorkPlace Extraweb interface. Shadowserver tracks more than 400 SMA1000 appliances exposed online, though their patch status and the number of honeypots are unknown. Previdian has not established whether the attempts successfully compromised any systems; SonicWall's Tuesday advisory had not flagged active exploitation.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/max-severity-sonicwall-sma1000-flaw-now-exploited-in-attacks/)

---
Canonical: https://techandbusiness.org/newswire/RHO5OdDfCPNYe3MEA6GHtx
Published: 2026-10-09T13:38:30.577Z
Story chronology: 2026-10-09T12:32:16.000Z
Retrieved: 2026-10-09T16:08:16.050Z
Publisher: Tech & Business (techandbusiness.org)
