CISA ordered federal agencies to patch a critical Splunk Enterprise vulnerability, CVE-2026-20253, by Sunday due to active exploitation. The flaw affects versions 10.2.0 to 10.2.3 and 10.0.0 to 10.0.6, allowing unauthenticated remote attackers to create or truncate files via a PostgreSQL sidecar endpoint.
Tap to vote and see what everyone thinks.
Summary by ByteBrief
Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosure