Back to Feed
VulnerabilitiesOct 8, 2026

SonicWall and Splunk Patch Critical Vulnerabilities

SonicWall and Splunk patch critical vulnerabilities allowing authentication bypass and code execution.

Summary

SonicWall released fixes for four vulnerabilities in SMA1000 appliances, including CVE-2026-102255 (CVSS 10.0), a pre-authenticated SSRF flaw enabling remote unauthenticated attackers to bypass authentication and perform unauthorized operations. Splunk patched dozens of flaws across Enterprise, MCP Server, and AWS Add-on products, including three critical bugs enabling arbitrary command execution and unauthorized access. Both vendors report no active exploitation in the wild at the time of disclosure.

Full text

Splunk and SonicWall on Wednesday announced patches for multiple critical- and high-severity vulnerabilities in their products, including flaws that could lead to arbitrary code execution. SonicWall rolled out fixes for four vulnerabilities in its SMA1000 appliances, urging users to update to versions 12.5.0-03082 and 12.4.3-03670 as soon as possible. The most severe of the issues, tracked as CVE-2026-102255 (CVSS score of 10), is a pre-authenticated SSRF bug that exists due to an unintended alternate access path. “By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations,” the company warned. The security updates also resolve two high- and one medium-severity vulnerability that could be exploited for remote code execution (RCE) and XSS attacks. “There is currently no evidence any of the vulnerabilities addressed in this release are being exploited in the wild. Please note that SSL-VPN running on SonicWall Firewall products are not affected by this vulnerability,” SonicWall said.Advertisement. Scroll to continue reading. Splunk announced fixes for dozens of security flaws in Splunk Enterprise, MCP Server, and Add-on for Amazon Web Services. The Splunk Enterprise updates fix three critical-severity bugs that could be exploited for arbitrary command execution, unauthorized access, and code injection. MCP Server received patches for a medium-severity defect that could allow an authenticated user to modify API settings to send requests to an attacker-controlled URL. Splunk also fixed multiple vulnerabilities in third-party packages in Splunk Enterprise and Splunk Add-on for Amazon Web Services. Additional information can be found on the company’s security advisories page. Related: TP-Link Faces State Lawsuits and New Scrutiny Over ISP Router Flaws Related: Chrome 155 Update Patches 247 Vulnerabilities Related: Android’s October 2026 Updates Patch 25 Vulnerabilities Related: Atlassian Patches Critical Vulnerability Affecting 8 Products Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Chrome 155 Update Patches 247 VulnerabilitiesASOS Confirms Cyberattack, Data BreachAndroid’s October 2026 Updates Patch 25 VulnerabilitiesAtlassian Patches Critical Vulnerability Affecting 8 ProductsFBI Arrests ‘Most Wanted’ Developer of Ploutus ATM MalwareApple to Tighten Full Disk Access Controls in macOS Amid AI RisksLong-Running NPM Malware Campaign Accumulates 40,000 Downloads8.8 Million Impacted by Data Breach at Denmark’s Central Person Register Latest News US Seeks Alleged Chinese Hafnium Hacker With $10 Million RewardRein Security Raises $25 Million to Guard AI Agents at RuntimeTP-Link Faces State Lawsuits and New Scrutiny Over ISP Router FlawsFake Decryption Tools Masked $11M Markup in Ransomware Recovery SchemeOracle Health Data Breach Tally Climbs to Nearly 20 MillionFortiBleed Attackers Locking Victims Out of Fortinet DevicesGeorgia Power, Alabama Power Data Breach Hits 400,000 AccountsQilin Ransomware Suspect Arrested in Japan, Extradited to Germany Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveChip Wentz has been appointed as SVP & CISO at Keurig Dr Pepper Inc.Lumen Technologies has named Kim Keever as CSO.Quantum Secure Encryption Corp. has appointed Joseph Hall as CIO.More People On The MoveExpert Insights AI Has Changed Attack Speed, Not Security Fundamentals As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals. (Joshua Goldfarb) Four Cyber Threats Harboring Big Plans for the Future - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin) Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • cve — CVE-2026-102255

Entities

SonicWall (vendor)Splunk (vendor)SonicWall SMA1000 (product)Splunk Enterprise (product)MCP Server (product)