Skip to content
You can now search across every topic, entity and event.What's new
Splunk
OrganisationUS

Splunk

US data-analytics and security-monitoring vendor.

Last refreshed: 24 July 2026 · Appears in 1 active topic

Timeline for Splunk

#11 15 Jul

Mentioned in: Oracle EBS gets a 3-day patch clock

Cybersecurity: Threats and Defences
#9 4 Jul

BOD 26-04, a fortnight of triage

Cybersecurity: Threats and Defences
View full timeline →

Background

Splunk Enterprise recorded its first-ever entry in CISA's Known Exploited Vulnerabilities catalogue in June 2026: CVE-2026-20253, an unauthenticated file-write flaw in the platform's PostgreSQL sidecar service, was added on 18 June with a 21 June federal deadline. WatchTowr Labs had already published a working exploit chained into Remote Code Execution, and Splunk confirmed active exploitation the same day as the KEV listing, having patched the flaw on 10 June in versions 10.2.4 and 10.0.7.

Splunk is a US data-analytics and security-monitoring company, best known for its Splunk Enterprise SIEM (Security Information and Event Management) platform, the tool most large security operations centres use to detect intrusions across their own networks. Cisco completed its acquisition of Splunk in 2024. Because Splunk sits inside the detection layer itself rather than at the network perimeter, a flaw here carries different stakes: an attacker able to compromise it can potentially blind the very system meant to catch them.

The Splunk Deadline passed without CISA publicly naming a non-compliant federal agency, one of two high-profile June KEV entries, alongside the triple-CVSS-10 Ubiquiti chain, to clear the fortnight without a compliance report.

Common Questions
What was Splunk's first CISA KEV entry?
CVE-2026-20253, an unauthenticated file-write flaw in Splunk Enterprise's PostgreSQL sidecar service, added to CISA's Known Exploited Vulnerabilities catalogue on 18 June 2026 with a 21 June Deadline.Source: Lowdown
Why does a flaw in Splunk matter more than a typical perimeter bug?
Splunk Enterprise is the SIEM platform most large security operations centres rely on to detect intrusions, so an attacker able to compromise it can blind the detection system itself rather than just gain another foothold.Source: Lowdown
Did CISA name an agency non-compliant over the Splunk KEV deadline?
No. The Splunk Deadline passed alongside the triple-CVSS-10 Ubiquiti KEV listing without CISA publicly naming any non-compliant federal agency.Source: Lowdown