SonicWall and Splunk Patch Critical Vulnerabilities: Essential Security Updates
SonicWall and Splunk have released security updates to address a series of critical and high-severity vulnerabilities impacting their respective products.
SonicWall Vulnerabilities
SonicWall disclosed fixes for four vulnerabilities affecting its SMA1000 appliances, urging users to upgrade to versions 12.5.0-03082 or 12.4.3-03670 immediately.
CVE-2026-102255
The most severe flaw, designated CVE-2026-102255 with a CVSS score of 10, involves a pre-authentication SSRF vulnerability stemming from an unintended alternate access path. This flaw allows a remote, unauthenticated attacker to manipulate the appliance into making requests on their behalf, potentially accessing internal systems and executing unauthorized actions.
Additional Fixes
The updates also resolve two high-severity and one medium-severity issues that could enable remote code execution and XSS attacks. SonicWall confirmed no evidence of active exploitation in the wild and clarified that SSL-VPN services on its firewall products remain unaffected.
Splunk Vulnerabilities
Splunk released patches for multiple vulnerabilities across its Splunk Enterprise platform, MCP Server, and the Add-on for Amazon Web Services.
Critical Flaws in Splunk Enterprise
The updates address three critical flaws in Splunk Enterprise that could permit arbitrary command execution, unauthorized access, and code injection.
MCP Server Fix
The MCP Server received a fix for a medium-severity vulnerability allowing authenticated users to alter API settings to redirect requests to attacker-controlled URLs.
Third-Party Components
Splunk resolved several issues in third-party components used within its enterprise and AWS add-on products. Further details are available in the company’s security advisories.
Both vendors emphasized the importance of timely patching to prevent potential exploitation. Organizations using affected systems are advised to apply the updates promptly and review their security configurations to mitigate risks. No confirmed instances of these vulnerabilities being exploited in active attacks have been reported to date.
