CISA: Splunk Enterprise flaw actively exploited, patch by Sunday
ID: 4f766a3b-b9dc-5f2b-94da-fde34c6d863f
STIX ID: report--4f766a3b-b9dc-5f2b-94da-fde34c6d863f
Feed Name: Bleeping Computer
Threat Score
CISA and Splunk warned of CVE-2026-20253, a critical Splunk Enterprise vulnerability (affecting versions 10.2.0–10.2.3 and 10.0.0–10.0.6) that allows unauthenticated remote actors to create or truncate arbitrary files via the PostgreSQL sidecar endpoint. Splunk released patches and mitigation guidance, proof-of-concept exploit code was published, and evidence of limited in-the-wild exploitation prompted CISA to order federal agencies to apply emergency patches by Sunday.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
