Threat reportVulnerabilityTL-2026-3176
SonicWall SMA1000 Pre-Auth SSRF (CVE-2026-102255, CVSS 10.0) and Critical Splunk Enterprise Vulnerabilities (CVE-2026-76268, CVE-2026-76281, CVE-2026-76284) Patched
SonicWall SMA1000 Pre-Auth SSRF (CVE-2026-102255, CVSS 10.0) (TL-2026-3176) is a critical-severity software vulnerability scored CVSS 10, first published 2026-10-08. It has no confirmed attribution, affects SonicWall SMA1000 (6210, 7210, 8200v), references 8 CVEs (CVE-2026-102255, CVE-2026-102256, CVE-2026-102257), maps to 6 MITRE ATT&CK techniques (T1059, T1078, T1133), and is covered by 9 detection rules and 8 indicators of compromise.
- CVSS
- 10/10Critical
- CVEs
- 8Referenced vulnerabilities
- Techniques
- 6MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 8Indicators of compromise
Key facts for TL-2026-3176
- Threat ID
- TL-2026-3176
- Severity
- CRITICAL
- CVSS
- 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, finance, health, technology, enterprise
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 8
Malware and tooling in SonicWall SMA1000 Pre-Auth SSRF (CVE-2026-102255, CVSS 10.0)
Malware and tooling: OrangeTail, RootRun, Sou5
How SonicWall SMA1000 Pre-Auth SSRF (CVE-2026-102255, CVSS 10.0) works
SonicWall patched a CVSS 10.0 pre-authentication SSRF (CVE-2026-102255) in the SMA1000 Appliance WorkPlace interface, together with a high-severity OS command injection, a high-severity Zip Slip and a medium-severity stored XSS. On 2026-10-07 Splunk patched three critical Splunk Enterprise flaws (command execution, access control, injection) and a medium-severity Splunk MCP Server token-leak SSRF. No in-the-wild exploitation of either set of flaws is reported.
SonicWall advisory SNWLID-2026-0017 (disclosed 2026-10-06) fixes four vulnerabilities in the SMA1000 series (physical models 6210 and 7210, virtual model 8200v). The headline flaw, CVE-2026-102255, is a pre-authentication server-side request forgery in the Appliance WorkPlace interface caused by an unintended alternate access path (CWE-441, CWE-918). NVD scores it CVSS 3.1 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). A remote unauthenticated attacker can direct the appliance to issue requests on their behalf and reach internal functionality to perform unauthorized operations. The SMA 100 Series and SSL-VPN on SonicWall firewalls are not affected. The other three flaws are CVE-2026-102256 (post-authentication OS command injection, CVSS 7.8, administrator login required), CVE-2026-102257 (Zip Slip path traversal with potential RCE, CVSS 7.2, in the Appliance Management Console) and CVE-2026-102258 (stored XSS, CVSS 5.5, administrator login required). Vulnerable builds are 12.4.3-03526 and older and 12.5.0-02952 and older. Fixed builds are 12.4.3-03670 and 12.5.0-03082 (and higher). SonicWall states there is currently no evidence that any of the flaws is exploited in the wild. Shadowserver tracks over 400 internet-exposed SMA1000 appliances.
This is the third time in 2026 that SonicWall has fixed a CVSS 10.0 pre-auth SSRF in SMA1000 WorkPlace. The earlier pairs, CVE-2026-15409/CVE-2026-15410 (July 14) and CVE-2026-83548/CVE-2026-83549 (September 1), were exploited as zero-days. Press reporting links the July activity to deployment of the Sou5, OrangeTail and RootRun malware and to ransomware-linked actors. This makes the new flaw a high-priority patching item even though no exploitation is reported yet. The credits are Benoit Sevens (Anthropic) and Brian Mariani (DigitalCanion SA).
Splunk published advisories on 2026-10-07 covering Splunk Enterprise 10.4.0-10.4.2, 10.2.0-10.2.6, 10.0.0-10.0.9 and 9.4.0-9.4.14 (fixed in 10.4.3, 10.2.7, 10.0.10 and 9.4.15). SVD-2026-1001 includes CVE-2026-76268 (CVSS 9.8, CWE-306), a missing authentication flaw in the Patroni REST API. An unauthenticated user with network access to the API on a search head cluster member could execute attacker-controlled operating system commands. Only the 10.4 and 10.2 lines are affected; 10.0.x and 9.4.x are not. The advisory also lists 17 additional medium-to-high CVEs. SVD-2026-1002 (Security Hardening) lists CVE-2026-76281 (CVSS 9.8, CWE-284 improper access control), CVE-2026-76282 (8.8), CVE-2026-76283 (7.6), CVE-2026-76284 (9.0, CWE-707 improper neutralization, consistent with the code injection flaw reported by SecurityWeek) and CVE-2026-76285 (4.4). The advisory gives no technical descriptions for these. SVD-2026-1004 covers CVE-2026-76286 (CVSS 5.3, CWE-918) in Splunk MCP Server below 1.2.1. A user with the mcp_tool_admin capability can configure a malicious API tool, and when a user with mcp_tool_execute runs it, the Splunk platform authentication token is sent to the attacker-configured URL. The attacker can then use the token to impersonate the victim. SVD-2026-1003 and SVD-2026-1005 are third-party package updates for Splunk Enterprise and the Splunk Add-on for Amazon Web Services. No exploitation or public PoC is reported for the Splunk flaws, and no IOCs or attribution have been published for either vendor's issues.
MITRE ATT&CK techniques used in TL-2026-3176
Execution
T1059 Command and Scripting Interpreter
Persistence
Initial Access
T1133 External Remote Services; T1190 Exploit Public-Facing Application
Credential Access
T1528 Steal Application Access Token
lateral-movement
T1550.001 Use Alternate Authentication Material: Application Access Token
Affected products and versions in SonicWall SMA1000 Pre-Auth SSRF (CVE-2026-102255, CVSS 10.0)
- SonicWall — SMA1000 (6210, 7210, 8200v)
Vulnerable versions: 12.4.3-03526 and older; 12.5.0-02952 and older
Fixed in: 12.4.3-03670; 12.5.0-03082 - Splunk — Splunk Enterprise
Vulnerable versions: 10.4.0-10.4.2; 10.2.0-10.2.6; 10.0.0-10.0.9; 9.4.0-9.4.14
Fixed in: 10.4.3; 10.2.7; 10.0.10; 9.4.15 - Splunk — Splunk MCP Server
Vulnerable versions: below 1.2.1
Fixed in: 1.2.1
Remediation for SonicWall SMA1000 Pre-Auth SSRF (CVE-2026-102255, CVSS 10.0)
Patches
- SonicWall SNWLID-2026-0017: SMA1000 12.4.3-03670 and 12.5.0-03082
- Splunk SVD-2026-1001 and SVD-2026-1002: Splunk Enterprise 10.4.3, 10.2.7, 10.0.10, 9.4.15
- Splunk SVD-2026-1004: Splunk MCP Server 1.2.1
Immediate actions
- Upgrade SonicWall SMA1000 to 12.4.3-03670 or 12.5.0-03082 (or higher) and review WorkPlace-facing exposure
- Upgrade Splunk Enterprise to 10.4.3, 10.2.7, 10.0.10 or 9.4.15 (or higher)
- Restrict network access to the Splunk Patroni REST API on search head cluster members to trusted management hosts
- Review SMA1000 WorkPlace and Splunk logs for anomalous unauthenticated requests or outbound requests from the appliance
Workarounds
- Disable the Splunk MCP Server app if it cannot be upgraded immediately
Longer-term hardening
- Restrict SMA1000 management console access to trusted networks and limit administrator accounts
- Audit Splunk roles that hold the mcp_tool_admin and mcp_tool_execute capabilities
- Treat repeated SMA1000 WorkPlace SSRF fixes in 2026 as a signal to monitor the appliance closely for compromise
CVEs associated with SonicWall SMA1000 Pre-Auth SSRF (CVE-2026-102255, CVSS 10.0)
CVE-2026-102255, CVE-2026-102256, CVE-2026-102257, CVE-2026-102258, CVE-2026-76268, CVE-2026-76281, CVE-2026-76284, CVE-2026-76286
Weaknesses (CWE) in SonicWall SMA1000 Pre-Auth SSRF (CVE-2026-102255, CVSS 10.0)
Timeline of SonicWall SMA1000 Pre-Auth SSRF (CVE-2026-102255, CVSS 10.0)
- SonicWall discloses CVE-2026-15409 and CVE-2026-15410 in SMA1000 WorkPlace; exploited as zero-days in multiple cases, with Sou5, OrangeTail and RootRun malware reported
- SonicWall discloses CVE-2026-83548 and CVE-2026-83549 in SMA1000, chained for remote code execution; exploitation in a case reported
- SonicWall publishes SNWLID-2026-0017 for CVE-2026-102255 (CVSS 10.0 pre-auth SSRF) and CVE-2026-102256/102257/102258; hotfixes 12.4.3-03670 and 12.5.0-03082 released
- Press reports no evidence of in-the-wild exploitation of CVE-2026-102255; Shadowserver tracks over 400 internet-exposed SMA1000 appliances
- Splunk publishes SVD-2026-1001 to 1005 covering Splunk Enterprise 10.4.3, 10.2.7, 10.0.10 and 9.4.15, Splunk MCP Server 1.2.1 and the AWS add-on; critical CVE-2026-76268 (Patroni REST API, CVSS 9.8)
- NVD publishes CVE-2026-102255 with CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H and CWE-441/CWE-918
- SecurityWeek reports SonicWall and Splunk patching critical vulnerabilities
Sources cited for SonicWall SMA1000 Pre-Auth SSRF (CVE-2026-102255, CVSS 10.0)
- SonicWall and Splunk Patch Critical Vulnerabilities
- SonicWall PSIRT SNWLID-2026-0017
- NVD CVE-2026-102255
- Help Net Security: SonicWall fixes pre-auth SSRF flaw in SMA 1000 appliances (CVE-2026-102255)
- BleepingComputer: SonicWall warns of max severity SSRF flaw in SMA1000 gateways
- The Hacker News: SonicWall patches CVSS 10.0 pre-auth flaw
- Splunk SVD-2026-1001: Security Vulnerabilities in Splunk Enterprise
- Splunk SVD-2026-1002: Security Hardening in Splunk Enterprise
- Splunk SVD-2026-1004: Security Vulnerability in Splunk MCP Server
- Splunk Security Advisories feed
Detection coverage for TL-2026-3176
As of 2026-10-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3176 across Splunk SPL, Microsoft KQL and Sigma, covering 8 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.