SonicWall and Splunk Patch Critical Vulnerabilities
Splunk and SonicWall on Wednesday announced patches for multiple critical- and high-severity vulnerabilities in their products, including flaws that could lead to arbitrary code execution.
SonicWall rolled out fixes for four vulnerabilities in its SMA1000 appliances, urging users to update to versions 12.5.0-03082 and 12.4.3-03670 as soon as possible.
The most severe of the issues, tracked as CVE-2026-102255 (CVSS score of 10), is a pre-authenticated SSRF bug that exists due to an unintended alternate access path.
“By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations,” the company warned.
The security updates also resolve two high- and one medium-severity vulnerability that could be exploited for remote code execution (RCE) and XSS attacks.
“There is currently no evidence any of the vulnerabilities addressed in this release are being exploited...
Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE