CISA Adds Splunk Flaw to KEV List
CISA added a Splunk Enterprise flaw to its known-exploited list and told agencies to patch by Sunday.
CVE-2026-20253 lets remote attackers reach a sensitive endpoint without credentials. CVSS 9.8 and actively exploited in the wild.
Affects Splunk Enterprise 10.2.0-10.2.3 and 10.0.0-10.0.6. Splunk Cloud is not affected (the vulnerable PostgreSQL sidecar isn't used there); on-prem only.
Patches have been available since June 10, in Splunk 10.2.4 and 10.0.7.
