Actively Exploited Splunk Enterprise Vulnerability Added to CISA KEV Catalog
- 事件类型
- Vulnerability
- 报告时间
- 2026-06-19 19:04:11
- 被攻击国家/地区
- USA
- 被攻击行业
- Software Development
- 被攻击组织
- splunk
- 被攻击域名
- splunk.com
- 攻击组织
- None
- 信息来源
- openweb
Original Text
查看原文
原文内容
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Splunk Enterprise vulnerability, CVE-2026-20253, to its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation in the wild. The flaw, rated 9.8 (Critical), allows unauthenticated attackers to create or modify files on vulnerable systems and could lead to remote code execution and full system compromise. Affected organizations are urged to apply security updates immediately, with federal agencies required to remediate the issue by the specified CISA deadline.