Exploited in the wild Splunk Enterprise rce Splunk patch-tuesday
Splunk CVE-2026-20253: CVSS 9.8 RCE Exploited in the Wild
CVE Tools coverage
CISA has added Splunk [CVE-2026-20253] to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild. The flaw affects Splunk Enterprise versions 10.2 (below 10.2.4) and 10.0 (below 10.0.7), where an authentication weakness in the PostgreSQL sidecar service can enable pre-authenticated remote code execution. Organizations should upgrade to 10.2.4 or 10.0.7 immediately (or disable the PostgreSQL sidecar service as a temporary mitigation) to reduce the risk of compromise.