DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 06:12:51ZSOURCES: 14CRITICAL: 31
⚠ ACTIVE ALERTS
@GossiTheDog CRITICAL — Sampled credentials from the FortiBleed dataset and confirmed they are authentic. Many of… /// @MsftSecIntel CRITICAL — Tracking FortiBleed downstream activity. Buyers of the FortiGate credential sets are… /// @TalosSecurity CRITICAL — FortiBleed is just one piece of a broader IAB operation. The same Russian-speaking actor… /// @MalwareHunterTeam CRITICAL — The Gentlemen RaaS internal data leak (May 2026, ~16GB) confirmed operators actively… /// @CrowdStrike CRITICAL — Gentlemen RaaS affiliates are deploying GentleKiller variants that specifically target…
31Critical Threats
18Active CVEs
19IOCs Tracked
11New Advisories
TLP:WHITE
Disclosure not limited. This advisory may be distributed publicly through any channel.
OFFICIAL ADVISORY // SVD-2026-0603 // PUBLISHED 2026-06-28
CERT/Splunk PSIRTCVE-2026-20253

Splunk Enterprise Unauthenticated Arbitrary File Write / RCE via PostgreSQL Sidecar — Actively Exploited (CVE-2026-20253)

CVE-2026-20253 (CVSS 9.8 Critical) is a missing-authentication flaw in Splunk Enterprise's PostgreSQL sidecar service endpoint that allows any network-reachable unauthenticated attacker to create or truncate arbitrary files, chainable into full pre-authenticated remote code execution. Splunk PSIRT confirmed limited in-the-wild exploitation on June 18, 2026, and CISA added the CVE to the KEV catalog the same day — marking the first Splunk vulnerability ever added to the KEV list. Shadowserver tracks over 1,400 internet-exposed Splunk instances, and public PoC code is available since June 12.

AFFECTED SYSTEM
SEVERITY
EXPLOIT
PATCH
Splunk Enterprise 10.2.0 – 10.2.3 (fixed in 10.2.4)
CRITICAL
PUBLIC
PATCHED
Splunk Enterprise 10.0.0 – 10.0.6 (fixed in 10.0.7)
CRITICAL
PUBLIC
PATCHED
Splunk Cloud Platform — NOT affected
CRITICAL
PUBLIC
PATCHED

Upgrade to Splunk Enterprise 10.4.0, 10.2.4, or 10.0.7 immediately — no workaround fully remediates the vulnerability. Restrict network access to Splunk management interfaces and the PostgreSQL sidecar service endpoint to trusted IP ranges only; the endpoint must not be reachable from untrusted networks or the internet. Implement network segmentation to isolate Splunk infrastructure. If an emergency maintenance window is unavailable, Splunk documents a temporary sidecar-disable workaround (note: this can break Edge Processor, OpAmp, and SPL2 data pipelines).

Review Splunk server logs for unexpected access to the PostgreSQL sidecar service endpoint (/v1/postgres/ paths) and anomalous file creation activity. Monitor for unexpected process execution from within the Splunk service context, particularly Python script execution not initiated by a known user or scheduled search. Watch EDR telemetry for anomalous child processes spawned by Splunk services. Alert on filesystem writes to /opt/splunk/etc/apps/ paths not correlated with administrative deployment actions.

  • https://advisory.splunk.com/advisories/SVD-2026-0603
  • https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  • https://nvd.nist.gov/vuln/detail/CVE-2026-20253
SHARE BRIEF:✕ Post on Xin Share on LinkedIn