For Part 2 we have 19 bulk disclosures from Splunk (10) and WatchGuard (9). We have two additional vendor disclosures from Wireshark. There are four vendor updates from Advantech, Moxa (2), and VMware. There are ten researcher reports on vulnerabilities in a product from Socomec. Finally, we have two exploits for products from Broadcom and PX4.
Bulk Disclosures – Splunk
SPL commands allowlist controls bypass in Splunk MCP Server app through “run_splunk_query” MCP tool,
Third-Party Package Updates in Splunk Enterprise - December 2025,
Improper Input Validation in “label” column field in Splunk Secure Gateway App,
Blind Server Side Request Forgery (SSRF) through Distributed Search Peers in Splunk Enterprise,
Incorrect permission assignment on Splunk Enterprise for Windows during new installation or upgrade,
URL validation bypass through Views Dashboard in Splunk Enterprise
Bulk Disclosures – WatchGuard
WatchGuard Firebox XPath Injection Vulnerability in Web CGI,
WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Gateway Wireless Controller,
WatchGuard Firebox Authenticated Out of Bounds Write in Management CLI Ping Command,
WatchGuard Firebox Authenticated Out of Bounds Write in Management CLI IPSec Configuration,
WatchGuard Firebox Authenticated Out of Bounds Write in certd.
Wireshark Advisories
Wireshark published an advisory that describes an infinite loop vulnerability (with publicly available exploit) in their MEGACO dissector. Wireshark has a new version that mitigates the vulnerability.
Wireshark published an advisory that describes an improperly controlled sequential memory allocation vulnerability (with publicly available exploit) in their HTTP3 dissector. The vulnerability was reported by Sébastien Féry. Wireshark has new versions that mitigate the vulnerability.
Advantech Update
Advantech published an update for their WISE-DeviceOn advisory that was originally published on November 18th, 2025. The new information includes adding download resource.
Moxa Updates
Moxa published an update for their Secure Routers advisory that was originally published on April 2nd, 2025, and most recently updated on October 27th, 2025. The new information includes updating the Solutions for the EDR-G9004 and EDR-G9010 Series.
Moxa published an update for their Secure Routers advisory that was originally published on on April 2nd, 2025, and most recently updated on October 27th, 2025. The new information includes updating the Solutions for the EDR-G9004 and EDR-G9010 Series.
VMware Update
Broadcom published an update for their vCenter Server advisory that was originally published on September 21s, 2021, and most recently updated on September 24th, 2021. The new information includes adding the new supplemental blog aka FAQ url.
Socomec Reports
Cisco Talos published ten reports for 14 vulnerabilities in the Socomec DIRIS Digiware M-70. The reports include proof-of-concept code. These are coordinated disclosures. Socomec has a new version that mitigates the vulnerabilities.
Broadcom Exploit
Laginimaineb published an exploit for an improper restriction of operations within the bounds of a memory buffer in the Broadcom BCM4355C0 Wi-Fi chips. Broadcom previously disclosed the vulnerability.
PX 4 Exploit
Indoushka published an exploit for a stack-based buffer overflow vulnerability in the PX4 drone autopilot. The vulnerability was reported to PX4, but there is no indication that a fix has been developed. This may be a 0-dayn vulnerability.