CVE-2026-20253
Sfruttamento noto · CISA KEV
CVSS 9.8 CRITICAL: in Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.3 and… EPSS 97% (100º percentile).
Data di correzione federale CISA 21 giu
Vulnerabilità · 102 giorni fa
Il problema non è solo l’RCE su un server Splunk. Se viene preso il nodo che raccoglie e interroga i log di sicurezza, l’attaccante può anche accecare il monitoraggio, alterare le tracce e leggere credenziali già salvate nel sistema.
CVE-2026-20253 colpisce Splunk Enterprise 10.2 prima di 10.2.4 e 10.0 prima di 10.0.7, con correzioni per Splunk Cloud a 10.4.2604.3 e 10.2.2510.14. La falla sta in un endpoint del PostgreSQL sidecar service che accetta operazioni su file senza controllare chi chiama; da lì si arriva all’esecuzione di codice. Splunk ha confermato uno sfruttamento limitato, WatchTowr ha pubblicato i dettagli con PoC e CISA l’ha messa nel catalogo KEV imponendo alle agenzie federali di chiudere entro il 21 giugno.
Ora la finestra di bonifica è compressa. Per chi usa Splunk come piano di controllo della sicurezza, il punto non è soltanto applicare una patch: un’istanza compromessa può nascondere attività successive e aprire la strada ad altri sistemi interni senza lasciare visibilità affidabile.
Sfruttamento noto · CISA KEV
CVSS 9.8 CRITICAL: in Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.3 and… EPSS 97% (100º percentile).
Data di correzione federale CISA 21 giu
4 fonti che coprono questa storia
Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253) - Help Net Security
CISA added CVE-2026-20253, a remotely exploitable vulnerability in Splunk Enterprise, to its Known Exploited Vulnerabilities catalog.
CISA: Splunk Enterprise flaw actively exploited, patch by Sunday
federal agencies to secure their systems by Sunday against a critical Splunk Enterprise vulnerability that is being exploited in attacks.
Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosure
CISA has given federal agencies only three days to patch CVE-2026-20253, which can be exploited for unauthenticated remote code execution.
Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication
Splunk issued security updates for a critical CVSS 9.8 vulnerability in Splunk Enterprise that allows unauthenticated remote code execution.
Part of the PlainSec briefing for 2026-06-14