Splunk released fixes for multiple product vulnerabilities, led by CVE-2026-20253, a critical unauthenticated remote code execution flaw in the PostgreSQL sidecar service used by Splunk Enterprise. The bug stems from missing authentication on the sidecar endpoint and can be abused for arbitrary file creation or truncation, enabling full compromise of the Splunk application environment. Affected Splunk Enterprise versions include releases earlier than 10.4.0, 10.2.4, and 10.0.7, while Splunk Cloud Platform fixes include 10.4.2604.3 for the related exposure.
Security sources reported that CVE-2026-20253 is being actively exploited in limited, targeted attacks, prompting CISA to add it to the Known Exploited Vulnerabilities catalog and require rapid federal remediation. Splunk’s broader June security updates also addressed CVE-2026-20251, a remote code execution issue tied to unsafe jsonpickle deserialization in KV Store data, along with additional SSRF, XSS, CSS injection, access-control bypass, and data-exposure flaws across Splunk Enterprise, Splunk Cloud Platform, Splunk Secure Gateway, and Splunk SOAR. Organizations unable to patch immediately were advised to disable the PostgreSQL sidecar service and hunt for signs of exploitation such as path traversal requests, unexpected pg_dump or pg_restore execution, suspicious dump files, and outbound connections to unknown PostgreSQL servers.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Palo Alto Networks published a product advisory for CVE-2026-0288 affecting PAN-OS User-ID Terminal Server Agent. The advisory identifies buffer overflow vulnerabilities in the component.
Palo Alto Networks published a product advisory for CVE-2026-0287 affecting PAN-OS. The advisory describes denial-of-service vulnerabilities in network traffic processing.
Palo Alto Networks published a product advisory for CVE-2026-0277 affecting Prisma Access Agent on iOS. The advisory identifies the issue as improper certificate validation.
ThreatAft reported that CVE-2026-20253, a critical unauthenticated remote code execution flaw in Splunk Enterprise's PostgreSQL sidecar service endpoint, was being actively exploited in the wild. The report described how missing authentication could enable file operations leading to arbitrary code execution and full compromise of the Splunk application environment.
CISA added CVE-2026-20253 to its Known Exploited Vulnerabilities catalog after the flaw was observed in active or limited targeted exploitation. The action required U.S. federal agencies to apply mitigations by June 21, 2026.
Palo Alto released security updates addressing multiple vulnerabilities across products including Cortex XSOAR, Prisma Access, Prisma Access Agent, Cortex XSIAM CommvaultSecurityIQ Marketplace, and PAN-OS. The notice highlighted CVE-2026-0274 and CVE-2026-0273 among the patched issues.
EG-FinCIRT published a notice highlighting Splunk's June 2026 security updates, including CVE-2026-20253 and CVE-2026-20251. The notice described affected products and urged organizations to deploy patches after testing.
Splunk released security updates to remediate multiple vulnerabilities across Splunk products, including CVE-2026-20253 in Splunk Enterprise. The fixes included versions such as Splunk Enterprise 10.0.7, 10.2.4, and later releases, with mitigation guidance to disable the PostgreSQL sidecar service if immediate upgrading was not possible.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
13 references tracked. Mallory keeps watching after this page renders.
security.paloaltonetworks.com
Open sourcesecurity.paloaltonetworks.com
Open sourcesecurity.paloaltonetworks.com
Open sourcesecurity.paloaltonetworks.com
Open sourcethreataft.com
Open sourceegfincirt.org.eg
Open sourceegfincirt.org.eg
Open sourcevulnerability.circl.lu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.