Vulnerabilities & Exploits

Splunk patch advisory hinges on the right branch

Splunk has published fixes for 22 vulnerabilities across Splunk Enterprise and Splunk Secure Gateway, including three critical and three high-severity issues. INCIBE-CERT says the affected Enterprise lines are 10.4.0-10.4.2, 10.2.0-10.2.6, 10.0.0-10.0.9, and 9.4.0-9.4.14, with Secure Gateway affected on older 3.10.11, 3.9.25, and 3.8.72 builds.

The set spans remote code execution, server-side request forgery, SQL injection, access-control failures, privilege escalation, and denial of service. The practical catch is that the fixes are branch-specific: moving to a newer major release is not enough unless it lands on the exact patched version for the branch you run, and four CVEs also require extra steps in Splunk's bulletin.

For teams running older supported Enterprise or Secure Gateway branches, the remaining exposure is not the product name but the specific release line they operate. Splunk's advisory leaves no single upgrade path that covers every deployment the same way.

1 source · 9h ago

CVEs in this update

7 CVEs

Across Splunk Enterprise, Splunk Secure Gateway.

1 critical · 0 high · 4 medium · 0 low

0 in CISA KEV · 0 with EPSS above 1%

Highest severity: CVE-2026-76268 · 9.8 CRITICAL

Timeline

Sources

Part of the PlainSec briefing for 2026-10-08

Every edition of this story: Splunk patch advisory hinges on the right branch

More from today