Skip to content
Critical Vulnerabilities in Splunk Enterprise Expose Systems to Attacks

Critical Vulnerabilities in Splunk Enterprise Expose Systems to Attacks

First seen 12 Jun 2026, 03:37 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 13, 2026 at 03:26 UTC
  • CVE-2026-20253 is a critical vulnerability with a CVSS score of 9.8.
  • Splunk Enterprise versions below 10.2.4 are affected by multiple vulnerabilities.
  • Immediate patching is recommended to mitigate risks of data exfiltration and unauthorized access.

Multiple high and critical vulnerabilities have been identified in Splunk Enterprise, allowing attackers to execute malicious scripts and exfiltrate sensitive data. The most severe vulnerability, CVE-2026-20253, has a CVSS score of 9.8 and affects versions below 10.2.4. Security advisories released on June 10, 2026, detail the potential for unauthorized file operations and sensitive information disclosure. Organizations using affected versions are at significant risk and are advised to apply vendor-released patches immediately. The vulnerabilities could lead to serious breaches if exploited, emphasizing the urgency for remediation.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 91d ago How this analysis works

Timeline

2026-06-10
Security advisories released for Splunk vulnerabilities
Multiple vulnerabilities in Splunk Enterprise were disclosed, including CVE-2026-20253, affecting versions below 10.2.4.
Cybersecuritynews
2026-06-10
CVE-2026-20253 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-11
Cybersecuritynews article published
The article highlights the critical vulnerabilities in Splunk Enterprise and their potential impact on security.
Cybersecuritynews
2026-06-12
HKCERT bulletin published
HKCERT issued a bulletin on multiple vulnerabilities in Splunk products, urging users to apply fixes.
Hkcert

More articles in this cluster (36)

Following this threat?

Track CVE-2026-20253 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed