SonicWall and Splunk Patch Critical Vulnerabilities
SonicWall patched a CVSS 10 pre-auth SSRF in SMA1000, and Splunk fixed critical command-execution flaws.
SonicWall patched four SMA1000 flaws, led by CVE-2026-102255, a CVSS 10 pre-authenticated SSRF that could let remote attackers reach internal functionality. The updates also cover remote code execution and XSS issues; SonicWall said there is no evidence of exploitation and that firewall SSL-VPN is unaffected. Splunk fixed dozens of bugs in Splunk Enterprise, MCP Server, and the Add-on for Amazon Web Services, including three critical Enterprise flaws enabling command execution, unauthorized access, and code injection.
- CVE-2026-102255 is a CVSS 10 pre-authentication SSRF in SonicWall SMA1000.
- SonicWall urges updates to 12.5.0-03082 or 12.4.3-03670; no exploitation reported.
- Splunk Enterprise fixes include three critical flaws allowing command execution and code injection.
- An MCP Server patch stops authenticated users from redirecting API requests to attacker URLs.
Vulnerabilities mentionedAll →
- CVE-2026-10225510.0—Pre-auth SSRF in SonicWall SMA1000 Work Place interfacepublished · SonicWall SMA1000 Appliance (Work Place interface)
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-102255 | Pre-auth SSRF in SonicWall SMA1000 Work Place interface CVE-2026-102255 is a pre-authentication server-side request forgery flaw in the Work Place interface of SonicWall SMA1000 appliances, caused by an unintended alternate access path (CWE-441 and CWE-918). A remote unauthenticated attacker can abuse that path so the appliance issues requests on their behalf, reaching internal functionality and performing unauthorized operations. Impact is directed requests and unauthorized internal operations from the gateway, not a confirmed remote code execution outcome in the supplied description. SonicWall SMA1000 secure-access gateways that expose the Work Place interface are affected; no version range is stated in the data. There is no public proof of concept and it is not listed in CISA KEV, so exploitation is none known; CVSS is not yet scored, though vendor reporting describes it as maximum severity and a fix has been announced. |
Full article304 words · extracted from securityweek.com · click to collapse
Splunk and SonicWall on Wednesday announced patches for multiple critical- and high-severity vulnerabilities in their products, including flaws that could lead to arbitrary code execution.
SonicWall rolled out fixes for four vulnerabilities in its SMA1000 appliances, urging users to update to versions 12.5.0-03082 and 12.4.3-03670 as soon as possible.
The most severe of the issues, tracked as CVE-2026-102255 (CVSS score of 10), is a pre-authenticated SSRF bug that exists due to an unintended alternate access path.
“By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations,” the company warned.
The security updates also resolve two high- and one medium-severity vulnerability that could be exploited for remote code execution (RCE) and XSS attacks.
“There is currently no evidence any of the vulnerabilities addressed in this release are being exploited in the wild. Please note that SSL-VPN running on SonicWall Firewall products are not affected by this vulnerability,” SonicWall said.
Advertisement. Scroll to continue reading.
Splunk announced fixes for dozens of security flaws in Splunk Enterprise, MCP Server, and Add-on for Amazon Web Services.
The Splunk Enterprise updates fix three critical-severity bugs that could be exploited for arbitrary command execution, unauthorized access, and code injection.
MCP Server received patches for a medium-severity defect that could allow an authenticated user to modify API settings to send requests to an attacker-controlled URL.
Splunk also fixed multiple vulnerabilities in third-party packages in Splunk Enterprise and Splunk Add-on for Amazon Web Services. Additional information can be found on the company’s security advisories page.
Related: TP-Link Faces State Lawsuits and New Scrutiny Over ISP Router Flaws
Related: Chrome 155 Update Patches 247 Vulnerabilities
Related: Android’s October 2026 Updates Patch 25 Vulnerabilities
Related: Atlassian Patches Critical Vulnerability Affecting 8 Products