SonicWall and Splunk released urgent security updates for multiple critical and high-severity vulnerabilities that could enable arbitrary code execution, unauthorized access, SSRF, and other attacks. SonicWall said its SMA1000 appliances are affected by a pre-authenticated SSRF flaw, while Splunk fixed serious issues across Splunk Enterprise, MCP Server, and the Add-on for Amazon Web Services. #SonicWall #SMA1000 #Splunk #SplunkEnterprise #MCPServer
Keypoints
- SonicWall patched four vulnerabilities in SMA1000 appliances.
- CVE-2026-102255 is a critical pre-authenticated SSRF flaw with a CVSS score of 10.
- The SonicWall bugs could enable RCE, XSS, and unauthorized operations.
- Splunk fixed dozens of issues in Splunk Enterprise, MCP Server, and AWS add-ons.
- Some Splunk flaws could allow arbitrary command execution, unauthorized access, and code injection.
Read More: https://www.securityweek.com/sonicwall-and-splunk-patch-critical-vulnerabilities/