Critical Splunk Enterprise flaw rated CVSS 9.8 is under active attack as CISA sets a June 21 patch deadline
Splunk's PSIRT says CVE-2026-20253, an unauthenticated remote-code-execution flaw in Splunk Enterprise at CVSS 9.8, is under limited exploitation; CISA set a June 21 patch deadline.
A critical security flaw in Splunk Enterprise rated 9.8 out of 10 is being exploited, and U.S. federal agencies have until June 21 to patch it. Tracked as CVE-2026-20253, the bug is an unauthenticated remote code execution vulnerability — meaning an attacker who can reach the system over the network needs no login to run code on it.
The stakes are high because of what Splunk Enterprise is: a widely deployed platform for collecting and searching machine data and security logs. According to Splunk's advisory, a PostgreSQL sidecar service endpoint performs no application-level authentication, allowing a network-reachable attacker to create or truncate arbitrary files and execute code on the underlying host. Successful exploitation can expose stored credentials, tamper with or delete security data, and let an intruder pivot to other internal systems.
The company has not described mass exploitation. Splunk's Product Security Incident Response Team (PSIRT) said it "became aware of limited exploitation of this vulnerability" in a June 18 update to advisory SVD-2026-0603, which it first published June 10. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) then added the flaw to its Known Exploited Vulnerabilities catalog and ordered federal civilian agencies to apply mitigations by June 21.
The fix is already available. The vulnerability affects Splunk Enterprise 10.2 versions below 10.2.4 and 10.0 versions below 10.0.7, and is patched in 10.2.4 and 10.0.7. Because the data a SIEM platform holds is precisely what a sophisticated intruder wants to read or quietly alter, the gap between disclosure on June 10 and confirmed exploitation days later leaves unpatched instances exposed past the federal deadline.
Founder and Chief Editor of Data Phoenix — a San Francisco Bay Area media and education platform focused on AI and Data.
More news

AWS releases six open-source Hugging Face deployment skills for SageMaker

Google Research releases MilleMiglia logistics benchmark generator

AWS launches AgentCore Runtime V2 with elastic memory and snapshot starts
