CVE-2026-20253
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: in Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.3 and… EPSS 97% (100th percentile).
CISA federal remediation date Jun 21
Vulnerabilities · 87 days ago
A Splunk server is not just another app when it sits in the monitoring path. If an attacker reaches this flaw, they can do more than run code on one box: they can interfere with security visibility, tamper with logs, and pull stored credentials from the platform that other teams trust to tell them what is happening.
CVE-2026-20253 affects Splunk Enterprise 10.2 before 10.2.4 and 10.0 before 10.0.7, with Splunk Cloud fixes at 10.4.2604.3 and 10.2.2510.14. The bug is in the PostgreSQL sidecar service endpoint, which lacks authentication and lets a network-reachable caller invoke file operations; public PoC followed quickly, Splunk confirmed limited in-the-wild exploitation, and CISA put it in KEV with a June 21 deadline for federal agencies.
That turns patching into a visibility problem as much as a code-execution problem. An attacker who owns Splunk can hide follow-on activity and use what the platform stores to move deeper into the environment.
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: in Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.3 and… EPSS 97% (100th percentile).
CISA federal remediation date Jun 21
4 sources covering this story
Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253) - Help Net Security
CISA added CVE-2026-20253, a remotely exploitable vulnerability in Splunk Enterprise, to its Known Exploited Vulnerabilities catalog.
CISA: Splunk Enterprise flaw actively exploited, patch by Sunday
federal agencies to secure their systems by Sunday against a critical Splunk Enterprise vulnerability that is being exploited in attacks.
Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosure
CISA has given federal agencies only three days to patch CVE-2026-20253, which can be exploited for unauthenticated remote code execution.
Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication
Splunk issued security updates for a critical CVSS 9.8 vulnerability in Splunk Enterprise that allows unauthenticated remote code execution.
Part of the PlainSec briefing for 2026-06-14