CVE-2026-20253 is a critical, unauthenticated remote code execution vulnerability in Splunk Enterprise that is under active in-the-wild exploitation, with observed attack vectors including path traversal sequences. The vulnerability has been added to CISA's Known Exploited Vulnerabilities catalog, requiring U.S. federal civilian agencies to apply mitigations by June 21, 2026. Organizations should prioritize patching and review systems for indicators of compromise, such as requests containing path traversal sequences or PostgreSQL connection parameters.
CISA has added CVE-2026-20253, a critical, remotely exploitable vulnerability in Splunk Enterprise, to its Known Exploited Vulnerabilities catalog, and ordered US federal civilian agencies to apply mitigations by June 21, 2026. In-the-wild exploitation has also been confirmed by the vendor and Resecurity, who said that its potential for full system compromise should push organizations to prioritize patching and review systems for indicators of compromise such as: Requests containing path traversal sequences (../) PostgreSQL connection parameters … More → The post Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253) appeared first on Help Net Security .