CVE-2026-20253
Sfruttamento noto · CISA KEV
CVSS 9.8 CRITICAL: in Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.3 and… EPSS 97% (100º percentile).
Data di correzione federale CISA 21 giu
Vulnerabilità ed exploit · Exploit zero-day
Il problema non è solo l’RCE su un server Splunk. Se viene preso il nodo che raccoglie e interroga i log di sicurezza, l’attaccante può anche accecare il monitoraggio, alterare le tracce e leggere credenziali già salvate nel sistema.
CVE-2026-20253 colpisce Splunk Enterprise 10.2 prima di 10.2.4 e 10.0 prima di 10.0.7, con correzioni per Splunk Cloud a 10.4.2604.3 e 10.2.2510.14. La falla sta in un endpoint del PostgreSQL sidecar service che accetta operazioni su file senza controllare chi chiama; da lì si arriva all’esecuzione di codice. Splunk ha confermato uno sfruttamento limitato, WatchTowr ha pubblicato i dettagli con PoC e CISA l’ha messa nel catalogo KEV imponendo alle agenzie federali di chiudere entro il 21 giugno.
Ora la finestra di bonifica è compressa. Per chi usa Splunk come piano di controllo della sicurezza, il punto non è soltanto applicare una patch: un’istanza compromessa può nascondere attività successive e aprire la strada ad altri sistemi interni senza lasciare visibilità affidabile.
4 fonti · 19 giu
Sfruttamento noto · CISA KEV
CVSS 9.8 CRITICAL: in Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.3 and… EPSS 97% (100º percentile).
Data di correzione federale CISA 21 giu
Help Net Security
Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253) - Help Net Security
CISA added CVE-2026-20253, a remotely exploitable vulnerability in Splunk Enterprise, to its Known Exploited Vulnerabilities catalog.
originaleBleepingComputer
CISA: Splunk Enterprise flaw actively exploited, patch by Sunday
federal agencies to secure their systems by Sunday against a critical Splunk Enterprise vulnerability that is being exploited in attacks.
originaleSecurityWeek
Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosure
CISA has given federal agencies only three days to patch CVE-2026-20253, which can be exploited for unauthenticated remote code execution.
originalePart of the PlainSec briefing for 2026-06-13
Every edition of this story: Splunk passa da bug critico a rischio per la visibilità