Dossier
Splunk Enterprise
Coverage of Splunk Enterprise in the Nexus archive.
- CISA: Splunk Enterprise flaw actively exploited, patch by Sunday
CISA has urged U.S. federal agencies to secure their systems by Sunday against a critical Splunk Enterprise vulnerability that is being exploited in attacks.
- Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication
Splunk has released security updates to address a critical flaw in Splunk Enterprise, allowing unauthenticated users to perform file operations and execute remote code. The vulnerability, CVE-2026-20253, has a CVSS score of 9.8 and affects versions below 10.2.4 and 10.0.7.