U.S. CISA adds Splunk Enterprise flaw to its Known Exploited Vulnerabilities catalog and urges agencies to fix it by Sunday
ID: 0cde064f-2403-5abc-9d21-5a66d08d3b59
STIX ID: report--0cde064f-2403-5abc-9d21-5a66d08d3b59
Feed Name: Security Affairs
Threat Score
CISA added CVE-2026-20253 (CVSS 9.8), an unauthenticated file creation/truncation flaw in the Splunk Enterprise PostgreSQL sidecar, to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch by June 21, 2026; Splunk confirmed limited active exploitation and advises upgrading to fixed releases or disabling the sidecar as a mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
