CVE Tools

The cve.tools Blog

Product updates, the weekly threat signal, and monthly trends — what shipped, what's exploited, and where we're heading.

Follow CVE Pulse on Telegram
Splunk Enterprise's open sidecar: the unauthenticated 9.8 that turns your SIEM into a foothold (CVE-2026-20253)
splunksiemcve-2026-20253

Splunk Enterprise's open sidecar: the unauthenticated 9.8 that turns your SIEM into a foothold (CVE-2026-20253)

CVE-2026-20253 is an unauthenticated arbitrary file-write in a PostgreSQL sidecar service that Splunk Enterprise 10.x ships alongside Edge Processor, OpAmp and SPL2 pipelines. It scores CVSS 9.8, sits at the 99.87th EPSS percentile, and is on CISA KEV with limited in-the-wild exploitation confirmed. Here's the missing-auth root cause, the exact affected versions, and how to patch — or disable the sidecar — without losing features.

Jul 31, 2026·6 min read
SharePoint's quiet 9.1: an unauthenticated auth-bypass that unlocks a still-unpatched RCE (CVE-2026-55040)
vuln-breakdownmicrosoftsharepoint

SharePoint's quiet 9.1: an unauthenticated auth-bypass that unlocks a still-unpatched RCE (CVE-2026-55040)

CVE-2026-55040 is an unauthenticated authentication bypass in on-prem SharePoint Server. It's not on KEV and has no public exploit - but a working Pwn2Own-grade exploit exists, it impersonates any user via forged JWTs, and patching it now breaks an unauthenticated-RCE chain whose second half is still unpatched. Who's exposed, how the chain works, and how to fix it.

Jul 21, 2026·12 min read