CVE Tools

Splunk CVE-2026-20253: CVSS 9.8 RCE Exploited in the Wild

Daily CyberSecurity (securityonline.info)By Do Son

Reported exploitedSplunk Enterprise

Our summary

CISA has added Splunk [CVE-2026-20253] to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild. The flaw affects Splunk Enterprise versions 10.2 (below 10.2.4) and 10.0 (below 10.0.7), where an authentication weakness in the PostgreSQL sidecar service can enable pre-authenticated remote code execution. Organizations should upgrade to 10.2.4 or 10.0.7 immediately (or disable the PostgreSQL sidecar service as a temporary mitigation) to reduce the risk of compromise.

Read at Daily CyberSecurity (securityonline.info)

Daily CyberSecurity (securityonline.info) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store