SONICWALL and Splunk have released patches addressing a set of critical and high-severity vulnerabilities across their products, which could allow attackers to bypass authentication, execute arbitrary code, or escalate privileges. The most serious flaw, CVE-2026-102255, is a pre-authenticated SSRF bug in SonicWall’s SMA1000 appliances. Exploitation could enable a remote unauthenticated attacker to direct the appliance to perform requests on behalf of the attacker and access internal functionality.
SonicWall notes that SSL-VPN running on its Firewall products is not affected. The company also patched two high-severity and one medium-severity issues that could lead to remote code execution (RCE) and cross-site scripting (XSS). SonicWall urges users to upgrade to versions 12.5.0-03082 or 12.4.3-03670 as soon as possible.
Splunk followed with fixes for dozens of vulnerabilities across Splunk Enterprise, MCP Server, and the Add-on for Amazon Web Services. Three critical-severity flaws in Splunk Enterprise could allow arbitrary command execution, unauthorised access, or code injection. MCP Server received a patch for a medium-severity defect that could let an authenticated user modify API settings to direct requests to an attacker-controlled URL.
Splunk also updated multiple third-party components within Splunk Enterprise and the Splunk Add-on for AWS. The advisory scope and CVEs are described in the respective Splunk security advisories; users should apply the updates promptly to mitigate potential exploitation.