DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 06:12:51ZSOURCES: 14CRITICAL: 31
⚠ ACTIVE ALERTS
@GossiTheDog CRITICAL — Sampled credentials from the FortiBleed dataset and confirmed they are authentic. Many of… /// @MsftSecIntel CRITICAL — Tracking FortiBleed downstream activity. Buyers of the FortiGate credential sets are… /// @TalosSecurity CRITICAL — FortiBleed is just one piece of a broader IAB operation. The same Russian-speaking actor… /// @MalwareHunterTeam CRITICAL — The Gentlemen RaaS internal data leak (May 2026, ~16GB) confirmed operators actively… /// @CrowdStrike CRITICAL — Gentlemen RaaS affiliates are deploying GentleKiller variants that specifically target…
31Critical Threats
18Active CVEs
19IOCs Tracked
11New Advisories
TLP:WHITE
Disclosure not limited. This advisory may be distributed publicly through any channel.
OFFICIAL ADVISORY // SVD-2026-0603 // PUBLISHED 2026-06-18

Splunk Enterprise CVE-2026-20253: Unauthenticated RCE via PostgreSQL Sidecar — CISA KEV / Actively Exploited

CVE-2026-20253 (CVSS 9.8 Critical) is a missing-authentication vulnerability in Splunk Enterprise's PostgreSQL sidecar service endpoint allowing unauthenticated attackers to create or truncate arbitrary files, which researchers chained to full pre-auth RCE. CISA added it to the KEV catalog on June 18 with a 3-day federal patch deadline. A public PoC (WatchTowr) is available, exploitation has been confirmed by Splunk PSIRT, and over 1,400 internet-exposed Splunk instances are tracked by Shadowserver. Compromise of Splunk (the SIEM) can blind defenders, tamper with detection logic, and expose all ingested log data.

AFFECTED SYSTEM
SEVERITY
EXPLOIT
PATCH
Splunk Enterprise 10.0.0 – 10.0.6 (fixed: 10.0.7)
CRITICAL
PUBLIC
PATCHED
Splunk Enterprise 10.2.0 – 10.2.3 (fixed: 10.2.4)
CRITICAL
PUBLIC
PATCHED
Splunk Enterprise 10.4.0+ (not affected)
CRITICAL
PUBLIC
PATCHED
Splunk Cloud Platform (not affected — PostgreSQL sidecar not used)
CRITICAL
PUBLIC
PATCHED

Upgrade Splunk Enterprise to 10.0.7, 10.2.4, or 10.4.0+. If immediate patching is not possible, disable the PostgreSQL Sidecar Service by adding 'disabled = true' under [splunk-launch] in $SPLUNK_HOME/etc/system/local/server.conf and restarting Splunk (note: disables Edge Processor, OpAmp, and SPL2 pipelines). Restrict network access to sidecar port to loopback (127.0.0.1) only via firewall rules.

Monitor for unauthorized HTTP requests to /v1/postgres/recovery/backup and /v1/postgres/recovery/restore endpoints. Check for unexpected modifications to /opt/splunk/etc/apps/splunk_secure_gateway/bin/ssg_enable_modular_input.py. Audit Splunk script directories for injected payloads. Review for new or modified cron entries and unexpected child processes spawned by the Splunk service account. Rotate all credentials and secrets if exposure is confirmed.

  • https://advisory.splunk.com/advisories/SVD-2026-0603
  • https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  • https://nvd.nist.gov/vuln/detail/CVE-2026-20253
  • https://thehackernews.com/2026/06/critical-splunk-enterprise-flaw-lets.html
SHARE BRIEF:✕ Post on Xin Share on LinkedIn