Splunk Fixes 17 Vulnerabilities Including Critical MCP Server RCE
ID: 01157cef-34e8-5e69-a577-15d2260cb58f
STIX ID: report--01157cef-34e8-5e69-a577-15d2260cb58f
Feed Name: GBHackers
Splunk released a security hardening update addressing 17 vulnerabilities across multiple products (Splunk MCP Server, Splunk AI Toolkit, Splunk Connect for Kafka, Cisco Talos Intelligence, and Splunk On-Call). The most severe is CVE-2026-76404, an authenticated unsafe deserialization RCE in MCP Server rated CVSS 9.1; the AI Toolkit contains numerous high-severity deserialization and authorization flaws. Administrators are advised to upgrade to the patched versions (e.g., MCP Server 1.2.1, AI Toolkit 6.0.1/6.0.0, Connect for Kafka 2.2.7, Talos 1.0.3) and review privileged account activity and application logs for anomalous behavior.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
