logo

Splunk CVE-2026-20253: CVSS 9.8 RCE Exploited in the Wild

ID: 725268cd-40bd-51cc-a8d4-f061ca925788

STIX ID: report--725268cd-40bd-51cc-a8d4-f061ca925788

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-06-18

Date Updated: 2026-06-18

Author: Do Son

...
...

This advisory details CVE-2026-20253 — a critical (CVSS 9.8) pre-authenticated RCE in the Splunk Enterprise PostgreSQL sidecar service that has been confirmed as actively exploited; affected Splunk Enterprise versions below 10.2.4 and 10.0.7 (and corresponding cloud versions) should be updated immediately or the sidecar disabled as a temporary workaround, with official patches 10.2.4 and 10.0.7 provided as the permanent fix.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.