Splunk and SonicWall on Wednesday announced patches for multiple critical- and high-severity vulnerabilities in their products, including flaws that could lead to arbitrary code execution.
SonicWall rolled out fixes for four vulnerabilities in its SMA1000 appliances, urging users to update to versions 12.5.0-03082 and 12.4.3-03670 as soon as possible.
The most severe of the issues, tracked as CVE-2026-102255 (CVSS score of 10), is a pre-authenticated SSRF bug that exists due to an unintended alternate access path.
“By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations,” the company warned.
The security updates also resolve two high- and one medium-severity vulnerability that could be exploited for remote code execution (RCE) and XSS attacks.
“There is currently no evidence any of the vulnerabilities addressed in this release are being exploited in the wild. Please note that SSL-VPN running on SonicWall Firewall products are not affected by this vulnerability,” SonicWall said.
Splunk announced fixes for dozens of security flaws in Splunk Enterprise, MCP Server, and Add-on for Amazon Web Services.
The Splunk Enterprise updates fix three critical-severity bugs that could be exploited for arbitrary command execution, unauthorized access, and code injection.
MCP Server received patches for a medium-severity defect that could allow an authenticated user to modify API settings to send requests to an attacker-controlled URL.
Splunk also fixed multiple vulnerabilities in third-party packages in Splunk Enterprise and Splunk Add-on for Amazon Web Services. Additional information can be found on the company’s security advisories page.
Related: TP-Link Faces State Lawsuits and New Scrutiny Over ISP Router Flaws
Related: Chrome 155 Update Patches 247 Vulnerabilities
Related: Android’s October 2026 Updates Patch 25 Vulnerabilities
Related: Atlassian Patches Critical Vulnerability Affecting 8 Products
