Threat reportVulnerabilityTL-2026-3176

SonicWall SMA1000 Pre-Auth SSRF (CVE-2026-102255, CVSS 10.0) and Critical Splunk Enterprise Vulnerabilities (CVE-2026-76268, CVE-2026-76281, CVE-2026-76284) Patched

criticalPATCHED

SonicWall SMA1000 Pre-Auth SSRF (CVE-2026-102255, CVSS 10.0) (TL-2026-3176) is a critical-severity software vulnerability scored CVSS 10, first published 2026-10-08. It has no confirmed attribution, affects SonicWall SMA1000 (6210, 7210, 8200v), references 8 CVEs (CVE-2026-102255, CVE-2026-102256, CVE-2026-102257), maps to 6 MITRE ATT&CK techniques (T1059, T1078, T1133), and is covered by 9 detection rules and 8 indicators of compromise.

CVSS
10/10Critical
CVEs
8Referenced vulnerabilities
Techniques
6MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
8Indicators of compromise

Key facts for TL-2026-3176

Threat ID
TL-2026-3176
Severity
CRITICAL
CVSS
10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, finance, health, technology, enterprise
Target regions
Global
Detection rules
9
Indicators of compromise
8

Malware and tooling in SonicWall SMA1000 Pre-Auth SSRF (CVE-2026-102255, CVSS 10.0)

Malware and tooling: OrangeTail, RootRun, Sou5

How SonicWall SMA1000 Pre-Auth SSRF (CVE-2026-102255, CVSS 10.0) works

SonicWall patched a CVSS 10.0 pre-authentication SSRF (CVE-2026-102255) in the SMA1000 Appliance WorkPlace interface, together with a high-severity OS command injection, a high-severity Zip Slip and a medium-severity stored XSS. On 2026-10-07 Splunk patched three critical Splunk Enterprise flaws (command execution, access control, injection) and a medium-severity Splunk MCP Server token-leak SSRF. No in-the-wild exploitation of either set of flaws is reported.

SonicWall advisory SNWLID-2026-0017 (disclosed 2026-10-06) fixes four vulnerabilities in the SMA1000 series (physical models 6210 and 7210, virtual model 8200v). The headline flaw, CVE-2026-102255, is a pre-authentication server-side request forgery in the Appliance WorkPlace interface caused by an unintended alternate access path (CWE-441, CWE-918). NVD scores it CVSS 3.1 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). A remote unauthenticated attacker can direct the appliance to issue requests on their behalf and reach internal functionality to perform unauthorized operations. The SMA 100 Series and SSL-VPN on SonicWall firewalls are not affected. The other three flaws are CVE-2026-102256 (post-authentication OS command injection, CVSS 7.8, administrator login required), CVE-2026-102257 (Zip Slip path traversal with potential RCE, CVSS 7.2, in the Appliance Management Console) and CVE-2026-102258 (stored XSS, CVSS 5.5, administrator login required). Vulnerable builds are 12.4.3-03526 and older and 12.5.0-02952 and older. Fixed builds are 12.4.3-03670 and 12.5.0-03082 (and higher). SonicWall states there is currently no evidence that any of the flaws is exploited in the wild. Shadowserver tracks over 400 internet-exposed SMA1000 appliances.

This is the third time in 2026 that SonicWall has fixed a CVSS 10.0 pre-auth SSRF in SMA1000 WorkPlace. The earlier pairs, CVE-2026-15409/CVE-2026-15410 (July 14) and CVE-2026-83548/CVE-2026-83549 (September 1), were exploited as zero-days. Press reporting links the July activity to deployment of the Sou5, OrangeTail and RootRun malware and to ransomware-linked actors. This makes the new flaw a high-priority patching item even though no exploitation is reported yet. The credits are Benoit Sevens (Anthropic) and Brian Mariani (DigitalCanion SA).

Splunk published advisories on 2026-10-07 covering Splunk Enterprise 10.4.0-10.4.2, 10.2.0-10.2.6, 10.0.0-10.0.9 and 9.4.0-9.4.14 (fixed in 10.4.3, 10.2.7, 10.0.10 and 9.4.15). SVD-2026-1001 includes CVE-2026-76268 (CVSS 9.8, CWE-306), a missing authentication flaw in the Patroni REST API. An unauthenticated user with network access to the API on a search head cluster member could execute attacker-controlled operating system commands. Only the 10.4 and 10.2 lines are affected; 10.0.x and 9.4.x are not. The advisory also lists 17 additional medium-to-high CVEs. SVD-2026-1002 (Security Hardening) lists CVE-2026-76281 (CVSS 9.8, CWE-284 improper access control), CVE-2026-76282 (8.8), CVE-2026-76283 (7.6), CVE-2026-76284 (9.0, CWE-707 improper neutralization, consistent with the code injection flaw reported by SecurityWeek) and CVE-2026-76285 (4.4). The advisory gives no technical descriptions for these. SVD-2026-1004 covers CVE-2026-76286 (CVSS 5.3, CWE-918) in Splunk MCP Server below 1.2.1. A user with the mcp_tool_admin capability can configure a malicious API tool, and when a user with mcp_tool_execute runs it, the Splunk platform authentication token is sent to the attacker-configured URL. The attacker can then use the token to impersonate the victim. SVD-2026-1003 and SVD-2026-1005 are third-party package updates for Splunk Enterprise and the Splunk Add-on for Amazon Web Services. No exploitation or public PoC is reported for the Splunk flaws, and no IOCs or attribution have been published for either vendor's issues.

MITRE ATT&CK techniques used in TL-2026-3176

Execution

T1059 Command and Scripting Interpreter

Persistence

T1078 Valid Accounts

Initial Access

T1133 External Remote Services; T1190 Exploit Public-Facing Application

Credential Access

T1528 Steal Application Access Token

lateral-movement

T1550.001 Use Alternate Authentication Material: Application Access Token

Affected products and versions in SonicWall SMA1000 Pre-Auth SSRF (CVE-2026-102255, CVSS 10.0)

  • SonicWall — SMA1000 (6210, 7210, 8200v)
    Vulnerable versions: 12.4.3-03526 and older; 12.5.0-02952 and older
    Fixed in: 12.4.3-03670; 12.5.0-03082
  • Splunk — Splunk Enterprise
    Vulnerable versions: 10.4.0-10.4.2; 10.2.0-10.2.6; 10.0.0-10.0.9; 9.4.0-9.4.14
    Fixed in: 10.4.3; 10.2.7; 10.0.10; 9.4.15
  • Splunk — Splunk MCP Server
    Vulnerable versions: below 1.2.1
    Fixed in: 1.2.1

Remediation for SonicWall SMA1000 Pre-Auth SSRF (CVE-2026-102255, CVSS 10.0)

Patches

  • SonicWall SNWLID-2026-0017: SMA1000 12.4.3-03670 and 12.5.0-03082
  • Splunk SVD-2026-1001 and SVD-2026-1002: Splunk Enterprise 10.4.3, 10.2.7, 10.0.10, 9.4.15
  • Splunk SVD-2026-1004: Splunk MCP Server 1.2.1

Immediate actions

  • Upgrade SonicWall SMA1000 to 12.4.3-03670 or 12.5.0-03082 (or higher) and review WorkPlace-facing exposure
  • Upgrade Splunk Enterprise to 10.4.3, 10.2.7, 10.0.10 or 9.4.15 (or higher)
  • Restrict network access to the Splunk Patroni REST API on search head cluster members to trusted management hosts
  • Review SMA1000 WorkPlace and Splunk logs for anomalous unauthenticated requests or outbound requests from the appliance

Workarounds

  • Disable the Splunk MCP Server app if it cannot be upgraded immediately

Longer-term hardening

  • Restrict SMA1000 management console access to trusted networks and limit administrator accounts
  • Audit Splunk roles that hold the mcp_tool_admin and mcp_tool_execute capabilities
  • Treat repeated SMA1000 WorkPlace SSRF fixes in 2026 as a signal to monitor the appliance closely for compromise

CVEs associated with SonicWall SMA1000 Pre-Auth SSRF (CVE-2026-102255, CVSS 10.0)

CVE-2026-102255, CVE-2026-102256, CVE-2026-102257, CVE-2026-102258, CVE-2026-76268, CVE-2026-76281, CVE-2026-76284, CVE-2026-76286

Weaknesses (CWE) in SonicWall SMA1000 Pre-Auth SSRF (CVE-2026-102255, CVSS 10.0)

CWE-441, CWE-918, CWE-306, CWE-284, CWE-707

Timeline of SonicWall SMA1000 Pre-Auth SSRF (CVE-2026-102255, CVSS 10.0)

  • SonicWall discloses CVE-2026-15409 and CVE-2026-15410 in SMA1000 WorkPlace; exploited as zero-days in multiple cases, with Sou5, OrangeTail and RootRun malware reported
  • SonicWall discloses CVE-2026-83548 and CVE-2026-83549 in SMA1000, chained for remote code execution; exploitation in a case reported
  • SonicWall publishes SNWLID-2026-0017 for CVE-2026-102255 (CVSS 10.0 pre-auth SSRF) and CVE-2026-102256/102257/102258; hotfixes 12.4.3-03670 and 12.5.0-03082 released
  • Press reports no evidence of in-the-wild exploitation of CVE-2026-102255; Shadowserver tracks over 400 internet-exposed SMA1000 appliances
  • Splunk publishes SVD-2026-1001 to 1005 covering Splunk Enterprise 10.4.3, 10.2.7, 10.0.10 and 9.4.15, Splunk MCP Server 1.2.1 and the AWS add-on; critical CVE-2026-76268 (Patroni REST API, CVSS 9.8)
  • NVD publishes CVE-2026-102255 with CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H and CWE-441/CWE-918
  • SecurityWeek reports SonicWall and Splunk patching critical vulnerabilities

Sources cited for SonicWall SMA1000 Pre-Auth SSRF (CVE-2026-102255, CVSS 10.0)

Detection coverage for TL-2026-3176

As of 2026-10-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3176 across Splunk SPL, Microsoft KQL and Sigma, covering 8 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
8 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats