Security1 publisherNot yet confirmed elsewhere2 min readPublished
SonicWall patches a CVSS 10 pre-login SSRF flaw in its SMA1000 appliances
SonicWall patched four SMA1000 flaws, led by CVE-2026-102255, a CVSS 10 request-forgery bug that an attacker can use without logging in. The company says none of the four is being exploited, so owners who update now are ahead of any known attack.
The Watch · Security desk

What happened
- SonicWall traces CVE-2026-102255 to an unintended alternate access path in the appliance.
- The other three fixes cover two high-severity flaws and one medium-severity flaw that can be exploited for remote code execution and cross-site scripting.
- SonicWall is urging SMA1000 users to update to version 12.5.0-03082 or 12.4.3-03670 as soon as possible.
- Splunk shipped fixes the same Wednesday, including three critical Splunk Enterprise bugs allowing command execution, unauthorized access and code injection.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure The bug is reached before the login step, so passwords and MFA do not protect an unpatched SMA1000 from anyone who can send it traffic.
- decision Teams that run SSL-VPN only on SonicWall firewalls can keep this release off their emergency change list, since SonicWall says that product is not affected.
- cost Fixed builds ship on both the 12.5 and 12.4 lines, so owners on 12.4 can patch without first moving to a new release line.
Server-side request forgery lets the attacker use the appliance's own position on the network. The SMA1000 sends the requests itself, so an outsider can reach functions meant only for internal callers [5]. "By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations," SonicWall said [5].
In that description, the SSRF stops at "unauthorized operations" [5]. Code execution sits in the other three fixes [6]. An SMA1000 on an older build has both problems at once: a request path that works before login, and at least one flaw that can be exploited for remote code execution [12]. The SecurityWeek report does not say whether those other flaws need a login, and it ties no threat actor or earlier campaign to SMA1000 appliances [6].
So this is a vendor patch, and no incident has been reported against it [7]. The no-exploitation status comes from SonicWall alone and describes the day of release, Wednesday [1][7]. I'd rank the bug on reach. Anyone who can send traffic to the appliance can attempt it [3].
Splunk patched a related kind of bug the same day [1]. Its MCP Server had a medium-severity defect that let an authenticated user change API settings so the product sent requests to an attacker-controlled URL [11]. Both bugs make a product send requests to a destination the attacker picks. Splunk's needs a logged-in user. SonicWall's needs none [3][11].
What to watch
- SonicWall publishing whether the two high-severity code-execution flaws require authentication, or whether the CVE-2026-102255 request path can reach them.
- Any revision to SonicWall's no-exploitation statement, or a public proof-of-concept for CVE-2026-102255.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence62
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Splunk and SonicWall on Wednesday announced patches for multiple critical- and high-severity vulnerabilities in their products.
- [2]
SonicWall rolled out fixes for four vulnerabilities in its SMA1000 appliances, urging users to update to versions 12.5.0-03082 and 12.4.3-03670 as soon as possible.
- [3]
The most severe of the SMA1000 issues, CVE-2026-102255, has a CVSS score of 10 and is a pre-authenticated server-side request forgery (SSRF) bug.
- [4]
CVE-2026-102255 exists due to an unintended alternate access path.
- [5]
"By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations."
- [6]
The SMA1000 updates also resolve two high-severity and one medium-severity vulnerability that could be exploited for remote code execution and XSS attacks.
- [7]
"There is currently no evidence any of the vulnerabilities addressed in this release are being exploited in the wild."
- [8]
"Please note that SSL-VPN running on SonicWall Firewall products are not affected by this vulnerability."
- [9]
Splunk announced fixes for dozens of security flaws in Splunk Enterprise, MCP Server, and Add-on for Amazon Web Services.
- [10]
The Splunk Enterprise updates fix three critical-severity bugs that could be exploited for arbitrary command execution, unauthorized access, and code injection.
- [11]
Splunk MCP Server received patches for a medium-severity defect that could allow an authenticated user to modify API settings to send requests to an attacker-controlled URL.
- [12]
An SMA1000 running a build older than the fixed releases carries both a pre-authentication SSRF path and at least one flaw that can be exploited for remote code execution.
Sources
1 independent publisher whose own reporting we read for this story.
- securityweek.comSonicWall and Splunk Patch Critical Vulnerabilities
1 article · October 8, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Vulnerability patching and upgrade cyclesFollow
- Server-Side Request ForgeryFollow
- Remote access appliancesFollow