Splunk disclosed and patched multiple vulnerabilities affecting Splunk Enterprise, Splunk Cloud Platform, and the MCP Server application, including two high-severity issues in its core platforms. The most serious, CVE-2026-20204, could allow a low-privileged user to achieve remote code execution by uploading a malicious file into the temporary application directory at $SPLUNK_HOME/var/run/splunk/apptemp, a weakness tied to improper temporary-file handling and insufficient isolation. Italian authorities also warned that newly identified flaws in Splunk products could expose sensitive information and allow arbitrary file writes on affected systems, urging organizations to review impacted version branches and apply vendor fixes.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
A security notice reported newly identified vulnerabilities in Splunk Enterprise and Splunk Cloud Platform, including two high-severity issues involving arbitrary file write and information disclosure. Organizations were urged to update affected versions according to Splunk security bulletins.
Splunk disclosed and patched multiple vulnerabilities affecting Splunk Enterprise, Splunk Cloud Platform, and the MCP Server application. The fixes included CVE-2026-20204, which could let a low-privileged user achieve remote code execution, and CVE-2026-20205, which could expose sessions and authorization tokens in clear text; Splunk advised upgrades and noted Cloud Platform updates were being applied directly.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.