Skip to content
You can now search across every topic, entity and event.What's new
Splunk Enterprise
ProductUS

Splunk Enterprise

Splunk's on-premises log-analytics and SIEM platform used by enterprise security operations centres.

Last refreshed: 24 June 2026

Key Question

Why does a flaw in Splunk Enterprise give attackers more than just another foothold?

Timeline for Splunk Enterprise

#8 18 Jun

Splunk lands its first-ever KEV entry

Cybersecurity: Threats and Defences
View full timeline →

Background

Splunk Enterprise is the on-premises edition of Splunk's log-analytics and SIEM (Security Information and Event Management) platform, acquired by Cisco in March 2024 for $28 billion. It is deployed in the security operations centres of a large proportion of Fortune 500 companies and major government departments, ingesting logs, alerts, and telemetry from across an organisation's infrastructure to give analysts a single pane of visibility into threats. On 18 June 2026, CISA added CVE-2026-20253 to the Known Exploited Vulnerabilities catalogue with a 21 June federal remediation Deadline: the first-ever Splunk entry in the catalogue's history. The flaw is an unauthenticated missing-authentication bug in Splunk Enterprise's PostgreSQL sidecar service that allows an attacker on the network to create or truncate arbitrary files without credentials. WatchTowr Labs published a working exploit chaining it into pre-authentication RCE (Remote Code Execution) before the KEV listing; Splunk confirmed active exploitation on the same day CISA acted. The patch shipped on 10 June in versions 10.2.4 and 10.0.7.

Splunk Enterprise sits in a structurally different position from the perimeter devices that dominate the KEV catalogue. Firewalls and VPN concentrators are the door; Splunk is the alarm system. An unauthenticated write that truncates Splunk's index and alert files before an intrusion begins gives the attacker a detection-evasion primitive built into the tool defenders watch through. The alarm can be silenced from inside the alarm system before anyone trips it. This is the same logic that made the CL-STA-1132 cluster's PAN-OS log-destruction capability significant: blind the detector, then move. Splunk's market dominance in the SOC means this is not an edge case on a niche product.

Cisco's 2024 acquisition of Splunk was framed partly as a security portfolio play, bundling Splunk's visibility platform with Cisco's network infrastructure and Talos threat-intelligence unit. CVE-2026-20253 is the first significant vulnerability to hit the combined entity's flagship security product post-acquisition and the first to clear the KEV threshold. The episode underscores a broader pattern on this beat: the detection and response layer is increasingly a target, not just the infrastructure it monitors.

Common Questions
What is Splunk Enterprise and why do security teams use it?
Splunk Enterprise is Cisco's on-premises SIEM and log-analytics platform, deployed in security operations centres to aggregate and analyse logs and alerts from across an organisation's infrastructure. It is the leading SIEM by installed base, particularly in Fortune 500 companies and government departments.Source: Splunk official product documentation
What is CVE-2026-20253 in Splunk Enterprise?
CVE-2026-20253 is an unauthenticated missing-authentication flaw in Splunk Enterprise's PostgreSQL sidecar service that allows a network attacker to create or truncate arbitrary files without credentials. WatchTowr Labs chained it into pre-auth RCE. CISA added it to KEV on 18 June 2026; Splunk patched it in versions 10.2.4 and 10.0.7.Source: CISA KEV catalogue and WatchTowr Labs disclosure, June 2026
Why is a Splunk vulnerability more dangerous than a firewall flaw?
Splunk is the detection system that security teams use to see attacks. A flaw that lets an attacker silently truncate Splunk's indexes and alert files before their intrusion begins eliminates the alarm before anyone triggers it. A perimeter breach grants entry; a SIEM breach grants invisibility.Source: CISA KEV analysis and event significance
Who now owns Splunk?
Cisco acquired Splunk in March 2024 for $28 billion, bundling its log-analytics and SIEM platform with Cisco's network infrastructure and Talos threat-intelligence unit.Source: Cisco Splunk acquisition announcement, 2024
Has Splunk ever been on the CISA KEV catalogue before?
No. CVE-2026-20253, listed on 18 June 2026, was the first-ever Splunk Enterprise entry in CISA's Known Exploited Vulnerabilities catalogue since its creation in 2021.Source: CISA KEV catalogue history
Source Material