Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

SonicWall and Splunk Patch Critical Vulnerabilities

Critical and high-severity vulnerabilities could allow attackers to bypass authentication, execute arbitrary code, and elevate their privileges.

Ivanti Fortinet Splunk Atlassian Nvidia Adobe vulnerability patches

Splunk and SonicWall on Wednesday announced patches for multiple critical- and high-severity vulnerabilities in their products, including flaws that could lead to arbitrary code execution.

SonicWall rolled out fixes for four vulnerabilities in its SMA1000 appliances, urging users to update to versions 12.5.0-03082 and 12.4.3-03670 as soon as possible.

The most severe of the issues, tracked as CVE-2026-102255 (CVSS score of 10), is a pre-authenticated SSRF bug that exists due to an unintended alternate access path.

“By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations,” the company warned.

The security updates also resolve two high- and one medium-severity vulnerability that could be exploited for remote code execution (RCE) and XSS attacks.

“There is currently no evidence any of the vulnerabilities addressed in this release are being exploited in the wild. Please note that SSL-VPN running on SonicWall Firewall products are not affected by this vulnerability,” SonicWall said.

Advertisement. Scroll to continue reading.

Splunk announced fixes for dozens of security flaws in Splunk Enterprise, MCP Server, and Add-on for Amazon Web Services.

The Splunk Enterprise updates fix three critical-severity bugs that could be exploited for arbitrary command execution, unauthorized access, and code injection.

MCP Server received patches for a medium-severity defect that could allow an authenticated user to modify API settings to send requests to an attacker-controlled URL.

Splunk also fixed multiple vulnerabilities in third-party packages in Splunk Enterprise and Splunk Add-on for Amazon Web Services. Additional information can be found on the company’s security advisories page.

Related: TP-Link Faces State Lawsuits and New Scrutiny Over ISP Router Flaws

Related: Chrome 155 Update Patches 247 Vulnerabilities

Related: Android’s October 2026 Updates Patch 25 Vulnerabilities

Related: Atlassian Patches Critical Vulnerability Affecting 8 Products

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

People on the Move

Chip Wentz has been appointed as SVP & CISO at Keurig Dr Pepper Inc.

Lumen Technologies has named Kim Keever as CSO.

Quantum Secure Encryption Corp. has appointed Joseph Hall as CIO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.