DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 06:12:51ZSOURCES: 14CRITICAL: 31
⚠ ACTIVE ALERTS
@GossiTheDog CRITICAL — Sampled credentials from the FortiBleed dataset and confirmed they are authentic. Many of… /// @MsftSecIntel CRITICAL — Tracking FortiBleed downstream activity. Buyers of the FortiGate credential sets are… /// @TalosSecurity CRITICAL — FortiBleed is just one piece of a broader IAB operation. The same Russian-speaking actor… /// @MalwareHunterTeam CRITICAL — The Gentlemen RaaS internal data leak (May 2026, ~16GB) confirmed operators actively… /// @CrowdStrike CRITICAL — Gentlemen RaaS affiliates are deploying GentleKiller variants that specifically target…
31Critical Threats
18Active CVEs
19IOCs Tracked
11New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-20253PUBLISHED: 2026-06-10
CRITICALCVE-2026-20253★ CISA KEV LISTED

Splunk Enterprise Unauthenticated Arbitrary File Write / Pre-Auth RCE via PostgreSQL Sidecar

VENDOR: Splunk (Cisco)//PRODUCT: Splunk Enterprise
9.8
CRITICAL
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
PUBLIC EXPLOIT

A missing authentication control (CWE-306) on the PostgreSQL sidecar service endpoint allows any network-reachable unauthenticated attacker to create or truncate arbitrary files on the Splunk server. Researchers at watchTowr Labs demonstrated that this file-write primitive is chainable into full pre-auth RCE by overwriting a scheduled Python script executed under the Splunk service account. CISA added CVE-2026-20253 to KEV on June 18, 2026 after Splunk PSIRT confirmed limited in-the-wild exploitation; public PoC code is available on GitHub and no workaround exists—only patching remediates the issue.

Attack Vector
NETWORK
Attack Complexity
LOW
Privs Required
NONE
User Interaction
NONE
Scope / Impact
UNCHANGED
C:H · I:H · A:H
AFFECTED VERSIONSSplunk Enterprise 10.0.0–10.0.6 (fixed in 10.0.7) and 10.2.0–10.2.3 (fixed in 10.2.4); AWS deployments vulnerable by default; 9.4.x and earlier not affected
  • https://advisory.splunk.com/advisories/SVD-2026-0603
  • https://thehackernews.com/2026/06/critical-splunk-enterprise-flaw-lets.html
  • https://www.picussecurity.com/resource/blog/splunk-cve-2026-20253-unauthenticated-remote-code-execution-vulnerability-explained
  • https://www.rescana.com/post/active-exploitation-of-critical-cve-2026-20253-in-splunk-enterprise-unauthenticated-rce-via-postgresql-sidecar-service
SHARE BRIEF:✕ Post on Xin Share on LinkedIn