www.securityweek.com 8 Oct 2026, 12:37 UTC

SonicWall and Splunk Patch Flaws That Could Enable Attacks

SonicWall and Splunk Patch Flaws That Could Enable Attacks
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

SONICWALL and Splunk have released patches addressing a set of critical and high-severity vulnerabilities across their products, which could allow attackers to bypass authentication, execute arbitrary code, or escalate privileges. The most serious flaw, CVE-2026-102255, is a pre-authenticated SSRF bug in SonicWall’s SMA1000 appliances. Exploitation could enable a remote unauthenticated attacker to direct the appliance to perform requests on behalf of the attacker and access internal functionality.

SonicWall notes that SSL-VPN running on its Firewall products is not affected. The company also patched two high-severity and one medium-severity issues that could lead to remote code execution (RCE) and cross-site scripting (XSS). SonicWall urges users to upgrade to versions 12.5.0-03082 or 12.4.3-03670 as soon as possible.

Splunk followed with fixes for dozens of vulnerabilities across Splunk Enterprise, MCP Server, and the Add-on for Amazon Web Services. Three critical-severity flaws in Splunk Enterprise could allow arbitrary command execution, unauthorised access, or code injection. MCP Server received a patch for a medium-severity defect that could let an authenticated user modify API settings to direct requests to an attacker-controlled URL.

Splunk also updated multiple third-party components within Splunk Enterprise and the Splunk Add-on for AWS. The advisory scope and CVEs are described in the respective Splunk security advisories; users should apply the updates promptly to mitigate potential exploitation.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline