radar.cysentrix
4 reports · 4 sources · tracked since 6d ago Actively exploited

Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication

AI synthesis Critical unauthenticated RCE in Splunk Enterprise (CVE-2026-20253) exploited in wild; CISA added to KEV, federal agencies must patch by June 21.

vulnerabilityzero day CVE-2026-20253
Why this ranks Transparent score: 29
coverage +12 source breadth +8 urgency +5 freshness +4

What changed

Coverage timeline

Every report remains linked to its original publisher.

  1. The Hacker News First observed

    Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication ↗

    Splunk has released security updates to address a critical security flaw in Splunk Enterprise that could be exploited to conduct unauthenticated file operations and even remote code execution. The vulnerability, tracked as CVE-2026-20253, is rated 9.8 on the CVSS scoring syste...

  2. Help Net Security Coverage expanded

    Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253) ↗

    CISA has added CVE-2026-20253, a critical, remotely exploitable vulnerability in Splunk Enterprise, to its Known Exploited Vulnerabilities catalog, and ordered US federal civilian agencies to apply mitigations by June 21, 2026. In-the-wild exploitation has also been confirmed ...

  3. SOCRadar Coverage expanded

    CVE-2026-20253: CISA Warns of Actively Exploited Splunk Enterprise RCE ↗

    CVE-2026-20253: CISA Warns of Actively Exploited Splunk Enterprise RCE Splunk Enterprise admins should prioritize patching CVE-2026-20253, a critical vulnerability that allows a network-reachable, unauthenticated attacker to create or truncate arbitrary files on the Splunk ser...