logo

Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosure

ID: b627f865-2f0d-5d96-80a7-4ef10f628ac7

STIX ID: report--b627f865-2f0d-5d96-80a7-4ef10f628ac7

Feed Name: CosmicBytez Labs

Threat Score
95/100

Date Published: 2026-06-19

Date Updated: 2026-06-19

...
...

A critical unauthenticated RCE in Splunk Enterprise (CVE-2026-20253) is being actively exploited following public disclosure and patch release; CISA added the CVE to its Known Exploited Vulnerabilities catalog with an unusually short three-day remediation mandate. The flaw allows remote arbitrary code execution via specially crafted search job requests, risking exposure and tampering of indexed security logs, lateral movement, and compromised incident response; the report describes exploitation timeline, impact, CISA guidance, and immediate remediation steps (apply patches, restrict network access, audit logs and accounts).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.