logo

CISA: Splunk Enterprise flaw actively exploited, patch by Sunday

ID: 4f766a3b-b9dc-5f2b-94da-fde34c6d863f

STIX ID: report--4f766a3b-b9dc-5f2b-94da-fde34c6d863f

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2026-06-19

Date Updated: 2026-06-19

Author: Sergiu Gatlan

...
...

CISA and Splunk warned of CVE-2026-20253, a critical Splunk Enterprise vulnerability (affecting versions 10.2.0–10.2.3 and 10.0.0–10.0.6) that allows unauthenticated remote actors to create or truncate arbitrary files via the PostgreSQL sidecar endpoint. Splunk released patches and mitigation guidance, proof-of-concept exploit code was published, and evidence of limited in-the-wild exploitation prompted CISA to order federal agencies to apply emergency patches by Sunday.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.