Analyst: The latest SSRF vulnerability was exploited within 24 hours of its disclosure by SonicWall SMA.
2026-10-11 17:34:15
According to CoinMeta, in the security notice SNWLID-2026-0017 issued on October 6th by SonicWall, there is currently no evidence that the vulnerabilities mentioned in the notice are being exploited. However, within 24 hours of its release, a honeypot network Previdian detected attempts to exploit the most severe vulnerability mentioned in the notice. The founder of Previdian, Ryan Dewhurst, confirmed this finding with BleepingComputer. The attack chain was specific and reproducible; it took advantage of an additional network interface at the workplace of SMA1000 to trigger server-side request forgery (SSRF), forcing devices to access its internal CouchDB services. The CVSS score for this vulnerability is 10.0, which indicates it is a bypass proxy vulnerability. This vulnerability, along with three other accompanying vulnerabilities, is listed in the same notice. Fix versions for SonicWall will be released in 12.4.3-03670 and 12.5.0-03082; there is currently no alternative solution available.
Bullish 0
Bearish 0
Source:Forkast
This content is for market information only and does not constitute investment advice.