• News/
  • bleepingcomputer-20260619103958

CISA: Splunk Enterprise flaw actively exploited, patch by Sunday

BleepingComputer
·
Sergiu Gatlan
·
Published Jun 19, 2026
·
Updated

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has urged federal agencies to secure their systems by Sunday against a critical Splunk Enterprise vulnerability that is being exploited in attacks. Tracked as CVE-2026-20253, this security flaw affects Splunk Enterprise (versions 10.2.0 to 10.2.3 and 10.0.0 to 10.0.6) and allows remote attackers without privileges to create or truncate arbitrary files on vulnerable devices via a PostgreSQL sidecar service endpoint. "The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials," the Splunk security team said in a security advisory published last week. On June 12, days after Splunk released security patches, WatchTowr published a technical write-up, shared proof-of-concept exploit code, and warned that the flaw can be abused for remote code execution attacks. On Wednesday, June 18, Splunk updated its advisory, urging customers to patch their systems as soon as possible due to evidence of in-the-wild exploitation. "In June 2026, the Splunk Product Security Incident Response Team (PSIRT) became aware of limited exploitation of this vulnerability. Splunk strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability," it said. Internet security watchdog group Shadowserver tracks over 1,400 Internet-exposed Splunk instances, most of them from North Americ...

Read full article

Affected Software

1 affected component
Splunk Enterprise>=10.2.0<=10.2.3, >=10.0.0<=10.0.6
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical vulnerability in Splunk Enterprise that is actively being exploited and requires immediate patching.

2

What vulnerability is highlighted in the article?

The article highlights the vulnerability tracked as CVE-2026-20253 in Splunk Enterprise.

3

What advice has CISA given to federal agencies regarding this vulnerability?

CISA has urged federal agencies to secure their systems against the vulnerability by patching by Sunday.

4

What versions of Splunk Enterprise are affected by the vulnerability?

The vulnerability affects Splunk Enterprise starting from version 10.2.

5

What is the exploit status of CVE-2026-20253?

CVE-2026-20253 is listed as actively exploited and is included in the Known Exploited Vulnerabilities (KEV) catalog.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203