
Splunk Enterprise
Splunk's on-premises log-analytics and SIEM platform used by enterprise security operations centres.
Last refreshed: 24 June 2026
Why does a flaw in Splunk Enterprise give attackers more than just another foothold?
Timeline for Splunk Enterprise
Splunk lands its first-ever KEV entry
Cybersecurity: Threats and DefencesBackground
Splunk Enterprise is the on-premises edition of Splunk's log-analytics and SIEM (Security Information and Event Management) platform, acquired by Cisco in March 2024 for $28 billion. It is deployed in the security operations centres of a large proportion of Fortune 500 companies and major government departments, ingesting logs, alerts, and telemetry from across an organisation's infrastructure to give analysts a single pane of visibility into threats. On 18 June 2026, CISA added CVE-2026-20253 to the Known Exploited Vulnerabilities catalogue with a 21 June federal remediation Deadline: the first-ever Splunk entry in the catalogue's history. The flaw is an unauthenticated missing-authentication bug in Splunk Enterprise's PostgreSQL sidecar service that allows an attacker on the network to create or truncate arbitrary files without credentials. WatchTowr Labs published a working exploit chaining it into pre-authentication RCE (Remote Code Execution) before the KEV listing; Splunk confirmed active exploitation on the same day CISA acted. The patch shipped on 10 June in versions 10.2.4 and 10.0.7.
Splunk Enterprise sits in a structurally different position from the perimeter devices that dominate the KEV catalogue. Firewalls and VPN concentrators are the door; Splunk is the alarm system. An unauthenticated write that truncates Splunk's index and alert files before an intrusion begins gives the attacker a detection-evasion primitive built into the tool defenders watch through. The alarm can be silenced from inside the alarm system before anyone trips it. This is the same logic that made the CL-STA-1132 cluster's PAN-OS log-destruction capability significant: blind the detector, then move. Splunk's market dominance in the SOC means this is not an edge case on a niche product.
Cisco's 2024 acquisition of Splunk was framed partly as a security portfolio play, bundling Splunk's visibility platform with Cisco's network infrastructure and Talos threat-intelligence unit. CVE-2026-20253 is the first significant vulnerability to hit the combined entity's flagship security product post-acquisition and the first to clear the KEV threshold. The episode underscores a broader pattern on this beat: the detection and response layer is increasingly a target, not just the infrastructure it monitors.