Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
3AUG

Splunk lands its first-ever KEV entry

3 min read
16:08UTC

CISA listed CVE-2026-20253 on 18 June, the first Splunk flaw ever added to the KEV catalogue. Splunk confirmed active exploitation the same day.

TechnologyDeveloping
Key takeaway

Corrupting the detector that security teams rely on outranks compromising one more edge device.

CISA added CVE-2026-20253 to the KEV (Known Exploited Vulnerabilities) catalogue on 18 June with a 21 June federal deadline 1. It is the first flaw in Splunk Enterprise ever to reach the catalogue. CISA's KEV list flags vulnerabilities confirmed as actively exploited; Splunk had never featured before. The bug is an unauthenticated missing-authentication flaw in a PostgreSQL (an open-source database) sidecar service, and it lets an attacker on the network create or truncate arbitrary files without logging in 2. WatchTowr Labs, a Singapore-based offensive research firm, published a working exploit and chained it into pre-auth RCE (Remote Code Execution). Splunk patched on 10 June in versions 10.2.4 and 10.0.7, then confirmed active exploitation eight days later 3.

Most KEV entries this year have been perimeter boxes: firewalls, VPN gateways, edge appliances. Splunk is different. It is the SIEM (Security Information and Event Management) platform that most large SOCs (security operations centres) run to see attacks at all. An intruder who can truncate Splunk's index and alert files before the main intrusion holds a detection-evasion primitive built into the tool defenders watch through. The alarm can be silenced from inside the alarm system before anyone trips it.

The same logic ran through CL-STA-1132, the state-sponsored cluster that destroyed PAN-OS forensic logs to erase its own tracks . Blind the defender, then move. May's Patch Tuesday shipped 120 fixes with no zero-days and read, briefly, like calm . June then produced six Microsoft zero-days and the first Splunk KEV inside a single fortnight, and the position of this one in the kill chain is what marks it out. A perimeter zero-day grants entry; an unauthenticated write on the SIEM grants invisibility, which is worth more to a patient intruder than another foothold.

Deep Analysis

In plain English

Most large organisations use Splunk Enterprise to watch for cyberattacks: it collects log data from thousands of systems and triggers alerts when something suspicious appears. Think of it as the CCTV control room for an organisation's entire digital estate. CVE-2026-20253 is a flaw in a background database process that Splunk runs alongside its main service. An attacker who can reach the network does not need a username or password to exploit it. By writing a malicious file to the right folder, they can force Splunk to load attacker-controlled code when it restarts, blinding the security team's own detection system. CISA added CVE-2026-20253 to its mandatory-patch list on 18 June 2026 with a three-day federal deadline. If your organisation runs Splunk Enterprise on-premises and has not applied the patch shipped on 10 June, treat this as critical.

Deep Analysis
Root Causes

Splunk Enterprise's PostgreSQL sidecar inherits the SIEM's privilege model without the SIEM's security scrutiny. Large enterprise products frequently bundle third-party data services as convenience sidecar processes; these sidecars receive less security review than the primary application and run under the same service account, creating a privilege escalation bridge that bypasses the primary application's authentication layer entirely.

WatchTowr published a working RCE chain for CVE-2026-20253 before CISA listed the CVE on 18 June and before most patch deployment cycles could respond. At 8 days from patch to confirmed exploitation, federal agencies that patched on day 3 still faced active threats from the 5-day window before the KEV listing, a gap the 3-day BOD 26-04 classification cannot close retrospectively.

What could happen next?
  • Risk

    An attacker who compromises Splunk via CVE-2026-20253 can suppress, falsify, or exfiltrate the log pipeline that security teams rely on to detect all other attacks across the estate, creating a detection blind spot that compounds every subsequent incident.

    Immediate · Assessed
  • Consequence

    Cyber insurers who list Splunk as a compensating control for SOC coverage in policy renewals will query whether the control was operative between patch availability (10 June) and confirmed exploitation confirmation (18 June), potentially affecting claims filed for incidents in that window.

    Short term · Reported
  • Opportunity

    Organisations using on-premises Splunk Enterprise now have a documented architectural reason to evaluate migration to Splunk Cloud or to mandate PostgreSQL sidecar network isolation as a configuration baseline, a change that reduces the attack surface regardless of future CVEs in the same component.

    Medium term · Suggested
First Reported In

Update #8 · CISA tears up the KEV deadline rulebook

BleepingComputer· 24 Jun 2026
Read original
Causes and effects
This Event
Splunk lands its first-ever KEV entry
An unauthenticated file-write on the SIEM most large security teams watch through turns the detection platform itself into a hiding place.
Different Perspectives
Group-IB
Group-IB
Group-IB, headquartered in Singapore, documented on 19 March that The Gentlemen began inside Qilin's own affiliate programme and split from it over a payment dispute. Its analysis makes this window's leak-site tally readable as a fracture inside one ransomware operation rather than the arrival of an unknown crew.
ENISA
ENISA
ENISA placed EU drinking water and wastewater in its cyber risk zone for the first time on 28 May, finding one in three water entities had never run a risk assessment. CISA's 30 July advisory to American operators reads as the operational sequel to a gap European regulators had already documented two months earlier.
House of Lords and NCSC
House of Lords and NCSC
The Cyber Security and Resilience Bill sits at House of Lords committee stage, its amendment paper running to 23 July. Separately, the NCSC guidance CISA cited when directing water operators to disconnect controllers is version 1.0 from March 2024, a two-year-old British document doing operational work in an American alert published last week.
heise online
heise online
heise online reported on 27 July that Russian state attackers, named as APT28, ran the hotel WiFi credential-harvesting campaign. Its attribution is firmer than ReliaQuest's own hedged low-to-medium confidence assessment of the same intrusion, a difference in national reporting posture rather than a settled dispute over who is responsible.
CISA and ReliaQuest
CISA and ReliaQuest
CISA compressed remediation deadlines under BOD 26-04 while, in the same window, telling water and wastewater operators to disconnect internet-exposed controllers rather than patch them. ReliaQuest, investigating the hotel WiFi campaign, held its assessment of the intrusion route at low-to-medium confidence and declined to name a state sponsor.
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.