logo

U.S. CISA adds Splunk Enterprise flaw to its Known Exploited Vulnerabilities catalog and urges agencies to fix it by Sunday

ID: 0cde064f-2403-5abc-9d21-5a66d08d3b59

STIX ID: report--0cde064f-2403-5abc-9d21-5a66d08d3b59

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-06-19

Date Updated: 2026-06-19

Author: Pierluigi Paganini

...
...

CISA added CVE-2026-20253 (CVSS 9.8), an unauthenticated file creation/truncation flaw in the Splunk Enterprise PostgreSQL sidecar, to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch by June 21, 2026; Splunk confirmed limited active exploitation and advises upgrading to fixed releases or disabling the sidecar as a mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.