- SonicWall and Splunk announced patches for multiple vulnerabilities, including flaws that could lead to arbitrary code execution.
- SecurityWeek said SonicWall’s most severe vulnerability is a pre-authenticated SSRF flaw with a CVSS score of 10.
- SonicWall said there is no evidence that the addressed vulnerabilities are being exploited in the wild.
SonicWall and Splunk announced patches for multiple vulnerabilities on Wednesday, including flaws that could lead to arbitrary code execution.
SecurityWeek said SonicWall’s most severe issue is a pre-authenticated SSRF vulnerability in SMA appliances with a CVSS score of 10. SonicWall said a remote unauthenticated attacker could direct an appliance to issue requests on the attacker’s behalf, reach internal functionality and perform unauthorized operations.
Splunk’s fixes cover Splunk Enterprise, MCP Server and the Add-on for Amazon Web Services. SecurityWeek said the Enterprise updates address bugs that could enable arbitrary command execution, unauthorized access and code injection.
On this page
SonicWall’s alternate access path could reach internal functionality
SecurityWeek said CVE-2026-102255 is a pre-authenticated SSRF vulnerability caused by an unintended alternate access path.
SonicWall said a remote unauthenticated attacker could potentially abuse the path to make the appliance issue requests and reach internal functionality.
SecurityWeek said the SonicWall updates also address two high-severity and one medium-severity vulnerability that could be exploited for remote code execution and cross-site scripting attacks.
Splunk patched Enterprise and MCP Server vulnerabilities
SecurityWeek said Splunk MCP Server received a patch for a medium-severity defect that could allow an authenticated user to modify API settings so requests go to an attacker-controlled URL.
Splunk said that in MCP Server versions below 1.2.1, a user with the `mcp_tool_admin` capability could configure a custom API tool to send requests to an attacker-controlled URL.
SonicWall said there is currently no evidence that the vulnerabilities addressed in its release are being exploited in the wild. It also said SSL-VPN running on SonicWall Firewall products is not affected.
| Product | Fixed version |
|---|---|
| Splunk MCP Server | 1.2.1 or higher |
| Splunk Enterprise | 10.4.3, 10.2.7, 10.0.10 or 9.4.15 or higher |
What to do now
- Update SonicWall SMA1000 appliances to versions 12.5.0-03082 and 12.4.3-03670.
- Upgrade Splunk MCP Server to version 1.2.1 or higher.
- Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15 or higher.
FAQ
What did SonicWall and Splunk announce on Oct 7, 2026?
SonicWall and Splunk announced patches for multiple vulnerabilities in their products, including flaws that could lead to arbitrary code execution.
What is CVE-2026-102255?
SecurityWeek described it as a pre-authenticated SSRF vulnerability caused by an unintended alternate access path. SecurityWeek gave the vulnerability a CVSS score of 10.
What could an attacker do with the SonicWall flaw?
SonicWall said a remote unauthenticated attacker could direct the appliance to issue requests on the attacker’s behalf, reach internal functionality and perform unauthorized operations.
Which Splunk MCP Server versions are affected?
Splunk said the MCP Server vulnerability affects versions below 1.2.1.
Were the SonicWall vulnerabilities exploited in the wild?
SonicWall said there is currently no evidence that the vulnerabilities addressed in its release are being exploited in the wild.
How should Splunk MCP Server users fix the issue?
Splunk says users of MCP Server versions below 1.2.1 should upgrade to version 1.2.1 or higher.
Sources
- Splunk Security Advisories Archive, SplunkPrimary
- SonicWall and Splunk Patch Critical Vulnerabilities, SecurityWeek
- SonicWall urges admins to patch critical RCE flaw in SMA 100 devices, BleepingComputer
- Sonicwall fixes critical flaw in SMA appliances, urges customers to check for compromise (CVE-2025-40599), Help Net Security
How we checked this story
| Claim | Source | Status |
|---|---|---|
| Splunk and SonicWall announced patches for multiple critical- and high-severity vulnerabilities in their products on Wednesday. | SonicWall, via SecurityWeek | Attributed |
| SecurityWeek said cVE-2026-102255 is a pre-authenticated SSRF vulnerability caused by an unintended alternate access path and has a CVSS score of 10. | SecurityWeek | Attributed |
| SonicWall said the alternate path could let a remote unauthenticated attacker make the appliance issue requests and reach internal functionality. | SonicWall, via SecurityWeek | Attributed |
| SecurityWeek said the SonicWall updates also address two high-severity and one medium-severity vulnerability that could enable remote code execution and cross-site scripting. | SecurityWeek | Attributed |
| SonicWall said there was no evidence that the addressed vulnerabilities were being exploited in the wild and that SSL-VPN on SonicWall Firewall products was unaffected. | SonicWall, via SecurityWeek | Attributed |
| Splunk announced fixes for dozens of security flaws in Splunk Enterprise, MCP Server, and the Add-on for Amazon Web Services. | Splunk, via SecurityWeek | Attributed |
| SecurityWeek said splunk Enterprise updates fix three critical-severity bugs that could enable arbitrary command execution, unauthorized access, and code injection. | SecurityWeek | Attributed |
| SecurityWeek said splunk MCP Server received a patch for a medium-severity defect that could let an authenticated user configure API requests to an attacker-controlled URL. | SecurityWeek | Attributed |
| Splunk says users unable to upgrade MCP Server should turn off or remove the Splunk MCP Server app. | Splunk | Confirmed |
Could not verify
- Whether the SonicWall vulnerabilities other than CVE-2026-102255 have assigned CVE identifiers is not established.
- Whether the Splunk vulnerabilities were exploited in the wild is not established.
- How many SonicWall and Splunk customers are affected is not established.
- Whether the SonicWall and Splunk vulnerabilities are linked is not established.



