CVE-2026-20253
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: in Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.3 and… EPSS 97% (100th percentile).
CISA federal remediation date Jun 21
Vulnerabilities · 95 days ago
The main risk here is not just the named product flaw. Splunk’s biggest leftover exposure sits in third-party components it bundles, so patching the core product can still leave other exploitable bugs in place, and Palo Alto’s issue sits in a specific trusted integration path rather than the main platform itself.
Splunk fixed CVE-2026-20253, a critical arbitrary file creation and truncation issue in Splunk Enterprise that unauthenticated attackers could reach through a PostgreSQL sidecar service endpoint. It also patched several other Enterprise and SOAR flaws, plus roughly three dozen vulnerabilities in third-party components. Palo Alto fixed CVE-2026-0274 in Cortex XSOAR and Cortex XSIAM, where improper credential validation in the CommvaultSecurityIQ integration could let attackers access and modify restricted resources, with no exploitation reported for either vendor’s flaws.
For operators, the practical boundary is wider than the headline CVE. If your stack depends on embedded libraries or trusted integrations, the residual risk can survive after the vendor patch lands.
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: in Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.3 and… EPSS 97% (100th percentile).
CISA federal remediation date Jun 21
EPSS 0.3% (20th percentile).
1 source covering this story
Splunk, Palo Alto Networks Patch Severe Vulnerabilities
The security defects could allow attackers to create or modify arbitrary files and access and modify protected resources.
Vendor digest: Palo Alto Networks
Part of the PlainSec briefing for 2026-06-12