Critical Splunk Enterprise RCE remains an urgent patch issue.
CVE-2026-20253, a critical Splunk Enterprise vulnerability, remains a major issue today because CISA ordered U.S. federal civilian agencies to apply mitigations by June 21, 2026. The flaw allows unauthenticated attackers to create or truncate arbitrary files through a PostgreSQL sidecar service endpoint, and Splunk’s own advisory rates it CVSS 9.8 Critical. Help Net Security reports that in-the-wild exploitation has been confirmed, while Splunk says it became aware of limited exploitation in June 2026. The affected versions include Splunk Enterprise 10.2 below 10.2.4 and 10.0 below 10.0.7. Splunk recommends upgrading to 10.4.0, 10.2.4, or 10.0.7 or higher; as a workaround, customers can disable the PostgreSQL sidecar service, with caveats for some features.