
Splunk
US data-analytics and security-monitoring vendor.
Last refreshed: 24 July 2026 · Appears in 1 active topic
Timeline for Splunk
Mentioned in: Oracle EBS gets a 3-day patch clock
Cybersecurity: Threats and DefencesBOD 26-04, a fortnight of triage
Cybersecurity: Threats and DefencesBackground
Splunk Enterprise recorded its first-ever entry in CISA's Known Exploited Vulnerabilities catalogue in June 2026: CVE-2026-20253, an unauthenticated file-write flaw in the platform's PostgreSQL sidecar service, was added on 18 June with a 21 June federal deadline. WatchTowr Labs had already published a working exploit chained into Remote Code Execution, and Splunk confirmed active exploitation the same day as the KEV listing, having patched the flaw on 10 June in versions 10.2.4 and 10.0.7.
Splunk is a US data-analytics and security-monitoring company, best known for its Splunk Enterprise SIEM (Security Information and Event Management) platform, the tool most large security operations centres use to detect intrusions across their own networks. Cisco completed its acquisition of Splunk in 2024. Because Splunk sits inside the detection layer itself rather than at the network perimeter, a flaw here carries different stakes: an attacker able to compromise it can potentially blind the very system meant to catch them.
The Splunk Deadline passed without CISA publicly naming a non-compliant federal agency, one of two high-profile June KEV entries, alongside the triple-CVSS-10 Ubiquiti chain, to clear the fortnight without a compliance report.