Critical Vulnerabilities in Splunk Enterprise Expose Systems to Attacks

Critical Vulnerabilities in Splunk Enterprise Expose Systems to Attacks

2h ago CybersecuritynewsHkcert 82% similarity 72.6
Share:

Article Content

Browse articles
ThreatCluster

Multiple high and critical vulnerabilities have been identified in Splunk Enterprise, allowing attackers to execute malicious scripts and exfiltrate sensitive data. The most severe vulnerability, CVE-2026-20253, has a CVSS score of 9.8 and affects versions below 10.2.4. Security advisories released on June 10, 2026, detail the potential for unauthorized file operations and sensitive information disclosure. Organizations using affected versions are at significant risk and are advised to apply vendor-released patches immediately. The vulnerabilities could lead to serious breaches if exploited, emphasizing the urgency for remediation.

Key Points: • CVE-2026-20253 is a critical vulnerability with a CVSS score of 9.8. • Splunk Enterprise versions below 10.2.4 are affected by multiple vulnerabilities. • Immediate patching is recommended to mitigate risks of data exfiltration and unauthorized access.

ThreatCluster AI

Timeline

2026-06-10
Security advisories released for Splunk vulnerabilities
Multiple vulnerabilities in Splunk Enterprise were disclosed, including CVE-2026-20253, affecting versions below 10.2.4.
Cybersecuritynews
2026-06-10
CVE-2026-20253 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-11
Cybersecuritynews article published
The article highlights the critical vulnerabilities in Splunk Enterprise and their potential impact on security.
Cybersecuritynews
2026-06-12
HKCERT bulletin published
HKCERT issued a bulletin on multiple vulnerabilities in Splunk products, urging users to apply fixes.
Hkcert

Community

Browse all →