SonicWall and Splunk Patch Critical Vulnerabilities
SonicWall patched a CVSS 10 pre-auth SSRF in SMA1000, and Splunk fixed critical command-execution flaws.
SonicWall patched four SMA1000 flaws, led by CVE-2026-102255, a CVSS 10 pre-authenticated SSRF that could let remote attackers reach internal functionality. The updates also cover remote code execution and XSS issues; SonicWall said there is no evidence of exploitation and that firewall SSL-VPN is unaffected. Splunk fixed dozens of bugs in Splunk Enterprise, MCP Server, and the Add-on for Amazon Web Services, including three critical Enterprise flaws enabling command execution, unauthorized access, and code injection.