Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SonicWall, Splunk Address Severe Security Flaws

SonicWall, Splunk Address Severe Security Flaws

Posted on October 8, 2026 By CWS

SonicWall and Splunk have released important updates addressing multiple high-risk vulnerabilities in their products. These updates were announced on Wednesday, focusing on critical flaws that may lead to arbitrary code execution and unauthorized access.

SonicWall’s Urgent Security Patches

SonicWall has urgently rolled out patches for four vulnerabilities within its SMA1000 devices. Users are strongly advised to upgrade to versions 12.5.0-03082 and 12.4.3-03670 without delay. The most severe issue, identified as CVE-2026-102255, possesses a CVSS score of 10 and involves a pre-authenticated server-side request forgery (SSRF) vulnerability.

This vulnerability could allow a remote, unauthenticated attacker to exploit an unintended access path, potentially enabling unauthorized requests and operations on the internal network. SonicWall’s update also addresses two high-severity and one medium-severity vulnerabilities that could lead to remote code execution (RCE) and cross-site scripting (XSS) attacks.

Addressing Security Flaws at Splunk

Splunk has similarly announced updates to rectify numerous security issues in its products, including Splunk Enterprise, MCP Server, and the Add-on for Amazon Web Services. These updates resolve critical vulnerabilities that could permit arbitrary command execution, unauthorized access, and code injection.

Particularly for MCP Server, a medium-severity flaw has been patched, which previously allowed authenticated users to alter API settings to redirect requests to potentially harmful URLs. Additionally, updates have been made to third-party packages within Splunk Enterprise and the AWS Add-on to enhance security.

Implications and Future Considerations

While there is no current evidence of these vulnerabilities being exploited in the wild, both companies emphasize the importance of applying these patches promptly to mitigate potential security risks. SonicWall reassures that its SSL-VPN running on Firewall products remains unaffected by these issues.

Users are encouraged to regularly check the security advisories provided by both SonicWall and Splunk for the latest information and updates. Keeping systems up to date is crucial in maintaining security and protecting against potential threats.

The swift response from SonicWall and Splunk underscores the ongoing challenges in cybersecurity and the necessity for continuous vigilance and timely updates.

Security Week News Tags:code execution, Cybersecurity, RCE, security patches, software updates, SonicWall, Splunk, SSRF, Vulnerabilities, XSS

Post navigation

Previous Post: Gitea Addresses Critical Security Flaws with New Update
Next Post: wolfSSH 1.6.0 Addresses Critical Security Vulnerabilities

Related Posts

Chinese Spies Impersonated US Lawmaker to Deliver Malware to Trade Groups: Report  Chinese Spies Impersonated US Lawmaker to Deliver Malware to Trade Groups: Report  Security Week News
Nvidia Triton Vulnerabilities Pose Big Risk to AI Models Nvidia Triton Vulnerabilities Pose Big Risk to AI Models Security Week News
Dutch Authorities Detain Hacker Tied to ShinyHunters Dutch Authorities Detain Hacker Tied to ShinyHunters Security Week News
CISA Alerts on SharePoint Security Flaw Exploitation CISA Alerts on SharePoint Security Flaw Exploitation Security Week News
O2 Service Vulnerability Exposed User Location O2 Service Vulnerability Exposed User Location Security Week News
Phishing Campaign Impacting Hundreds of Firms Uncovered Phishing Campaign Impacting Hundreds of Firms Uncovered Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Rethinking Security Awareness Training in Modern Enterprises
  • wolfSSH 1.6.0 Addresses Critical Security Vulnerabilities
  • SonicWall, Splunk Address Severe Security Flaws
  • Gitea Addresses Critical Security Flaws with New Update
  • US Offers $10 Million for Information on Chinese Hacker

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Rethinking Security Awareness Training in Modern Enterprises
  • wolfSSH 1.6.0 Addresses Critical Security Vulnerabilities
  • SonicWall, Splunk Address Severe Security Flaws
  • Gitea Addresses Critical Security Flaws with New Update
  • US Offers $10 Million for Information on Chinese Hacker

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark