Splunk Enterprise security update for CVE-2026-20253
Security Patch Release
Summary
Hide ▲
Show ▼
Splunk released security updates for CVE-2026-20253, fixing a critical Splunk Enterprise flaw that could enable unauthenticated file operations and remote code execution. The update covers Splunk Enterprise 10.0.0 to 10.0.6 and 10.2.0 to 10.2.3, with fixes in 10.0.7 and 10.2.4. Splunk Cloud is not impacted.
Related Happenings
Fortinet security patch release for CVE-2026-25089
Security Patch Release
H score44
First: 10.06.2026 18:10
Last: 10.06.2026 18:10
Sources 1
About this happening:
Fortinet, Ivanti, and SAP released security updates that address multiple critical vulnerabilities across FortiSandbox, Ivanti Sentry, and SAP prod...
Fortinet security patch release for CVE-2026-25089
Security Patch ReleaseAbout this happening: Fortinet, Ivanti, and SAP released security updates that address multiple critical vulnerabilities across FortiSandbox, Ivanti Sentry, and SAP prod...
Latest development: 11.06.2026 09:20
Shadowserver reported large-scale exploitation attempts against Internet-exposed Ivanti Sentry gateways after CVE-2026-10520 was patched in R10.5.2, R10.6.2, and R10.7.1, saying it saw 19 vulnerable instances and at least 2 backdoored systems and warning that unpatched devices were most likely compromised.
Ivanti security patch release for CVE-2026-8043
Security Patch Release
H score25
First: 18.05.2026 13:54
Last: 18.05.2026 13:54
Sources 1
About this happening:
Ivanti, Fortinet, SAP, Broadcom, and n8n released security fixes on 2026-05-18 for flaws that could enable authentication bypass, remote code execution, SQL...
Ivanti security patch release for CVE-2026-8043
Security Patch ReleaseAbout this happening: Ivanti, Fortinet, SAP, Broadcom, and n8n released security fixes on 2026-05-18 for flaws that could enable authentication bypass, remote code execution, SQL...
SAP May 2026 security updates for Commerce Cloud and S/4HANA (15 vulnerabilities)
Security Patch Release
H score38
First: 12.05.2026 14:04
Last: 12.05.2026 14:04
Sources 1
About this happening:
SAP released its May 2026 security updates for 15 vulnerabilities across Commerce Cloud, S/4HANA, and other products, including two critical flaws that can...
SAP May 2026 security updates for Commerce Cloud and S/4HANA (15 vulnerabilities)
Security Patch ReleaseAbout this happening: SAP released its May 2026 security updates for 15 vulnerabilities across Commerce Cloud, S/4HANA, and other products, including two critical flaws that can...
Microsoft April 2026 Patch Tuesday security update (165 CVEs)
Security Patch Release
H score62
First: 15.04.2026 00:22
Last: 15.04.2026 00:22
Sources 1
About this happening:
Microsoft shipped April 2026 Patch Tuesday updates covering 165 CVEs, including an actively exploited zero-day and a publicly disclosed flaw, creating immediat...
Microsoft April 2026 Patch Tuesday security update (165 CVEs)
Security Patch ReleaseAbout this happening: Microsoft shipped April 2026 Patch Tuesday updates covering 165 CVEs, including an actively exploited zero-day and a publicly disclosed flaw, creating immediat...
SAP security patch release for CVE-2019-17571
Security Patch Release
H score42
First: 11.03.2026 14:26
Last: 11.03.2026 14:26
Sources 1
About this happening:
SAP released security updates for two critical flaws in FS-QUO and NetWeaver Enterprise Portal Administration, reducing the risk of arbitrary code execution on...
SAP security patch release for CVE-2019-17571
Security Patch ReleaseAbout this happening: SAP released security updates for two critical flaws in FS-QUO and NetWeaver Enterprise Portal Administration, reducing the risk of arbitrary code execution on...
Timeline
-
13.06.2026 16:23 3 articles · 1mo ago
Splunk releases fixes for CVE-2026-20253 in Splunk Enterprise
Mitigation Patch UpdateSplunk released security updates for CVE-2026-20253 in Splunk Enterprise, fixing an unauthenticated flaw in the PostgreSQL sidecar service endpoint that could allow arbitrary file creation or truncation and possible remote code execution. Affected releases are Splunk Enterprise 10.0.0 to 10.0.6 and 10.2.0 to 10.2.3, with fixes in 10.0.7 and 10.2.4; Splunk Enterprise 10.4 is not affected and Splunk Cloud is not impacted. watchTowr Labs detailed a pre-auth attack path through /v1/postgres/recovery/backup and /v1/postgres/recovery/restore that could overwrite a Python script such as /opt/splunk/etc/apps/splunk_secure_gateway/bin/ssg_enable_modular_input.py.
Show sources
- Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication — thehackernews.com — 13.06.2026 16:23
- Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication — thehackernews.com — 13.06.2026 16:23
- CISA: Splunk Enterprise flaw actively exploited, patch by Sunday — www.bleepingcomputer.com — 19.06.2026 13:39