LIVE · cybersecurity feed
Live wire
vendor1 exploited in the wild

Splunk

56 CVEs published in the last four months and 2 stories. Exploited flaws first.

Critical6
High46
Medium4
Exploited (KEV)1

Patch these first

CVECVSSSeverityProductSummaryPublished
CVE-2026-20253exploited9.8criticalsplunkIn Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create87d ago

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-20253exploited9.8criticalsplunkIn Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create87d ago
CVE-2026-763129.4criticalsplunkIn Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who can read the H17d ago
CVE-2026-763119.4criticalsplunkIn Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedde17d ago
CVE-2026-763109.4criticalsplunkIn Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedde17d ago
CVE-2026-764049.1criticalmodel context protocol serverIn Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary co17d ago
CVE-2026-202669.1criticalai toolkitIn Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS com80d ago
CVE-2026-763158.8highsplunkIn Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "p17d ago
CVE-2026-763958.8highai toolkitIn Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code o17d ago
CVE-2026-202518.8highsplunkIn Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.87d ago
CVE-2026-763528.8highsplunkIn Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "p17d ago
CVE-2026-763518.8highsplunkIn Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 317d ago
CVE-2026-763178.8highsplunkIn Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "p17d ago
CVE-2026-763138.8highsplunkIn Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "p17d ago
CVE-2026-763148.8highsplunkIn Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "p17d ago
CVE-2026-763168.8highsplunkIn Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.9, and 9.4.14, an unauthenticated user who can reach the 17d ago
CVE-2026-763508.8highsplunkIn Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the schedule17d ago
CVE-2026-763358.8highsplunkIn Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an authenticated user who does not hold a 17d ago
CVE-2026-762538.8highsplunkIn Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the schedule17d ago
CVE-2026-763198.8highsplunkIn Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a low-privileged user that does not hold t17d ago
CVE-2026-762598.8highsplunkIn Splunk Enterprise for Windows versions below 10.4.2, 10.2.6, 10.0.9, 9.4.13, and 9.3.14, a local user with acce17d ago
CVE-2026-202968.3highsplunkIn Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 152d ago
CVE-2026-763918.3highai toolkitIn Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could run 17d ago
CVE-2026-763948.3highai toolkitIn Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not hold the "admin" or "power" Splunk r17d ago
CVE-2026-764028.2highconnect for kafkaIn Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Represen17d ago
CVE-2026-763388.1highsplunkIn Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has access to 17d ago
CVE-2026-763318.1highsplunkIn Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "p17d ago
CVE-2026-763548.1highsplunkIn Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "p17d ago
CVE-2026-763568.1highsoarIn Splunk SOAR versions below 8.6.0, an unauthenticated user could spoof the source IP address in a crafted reques17d ago
CVE-2026-763878.1highenterprise securityIn Splunk Enterprise Security versions below 8.6.1, a user who holds a Splunk Enterprise Security role that contai17d ago
CVE-2026-763888.1highenterprise securityIn Splunk Enterprise Security versions below 8.6.1, a user who holds the ess_analyst Splunk Enterprise Security ro17d ago
CVE-2026-763978.1highai toolkitIn Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all re17d ago
CVE-2026-763998.1highai toolkitIn Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided sche17d ago
CVE-2026-763447.7highsplunkIn Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "p17d ago
CVE-2026-763577.6highsoarIn Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could submit a crafted file path 17d ago
CVE-2026-202527.6highsplunkIn Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 187d ago
CVE-2026-762547.5highsplunkIn Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, 9.4.14, and 9.3.14, an unauthenticated user could caus17d ago
CVE-2026-202397.5highsplunkIn Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.108d ago
CVE-2026-762627.5highsplunkIn Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could read Prometheus service metrics fro17d ago
CVE-2026-763967.5highai toolkitIn Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the schedule_search capability could caus17d ago
CVE-2026-763557.5highsplunkIn Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could retrieve the information contained 17d ago
CVE-2026-763627.4highsoarIn Splunk SOAR versions below 8.6.0, an unauthenticated user who can observe or alter network traffic between Splu17d ago
CVE-2026-764037.4highconnect for kafkaIn Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user positioned in the network path could rea17d ago
CVE-2026-763217.3highsplunkIn Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could inject arbit17d ago
CVE-2026-763257.3highsplunkIn Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role c17d ago
CVE-2026-201637.2highsplunkIn Splunk Enterprise versions below 10.2.0, 10.0.4, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10178d ago
CVE-2026-202977.2highsplunkIn Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, 9.4.13, and 9.3.14, and Splunk Cloud Platform versions52d ago
CVE-2026-763327.1highsplunkIn Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an aut17d ago
CVE-2026-762517.1highsplunkIn Splunk Enterprise versions below 10.4.2, 10.2.6, and 10.0.9, a user who does not hold the "admin" or "power" Sp17d ago
CVE-2026-763367.1highsplunkIn Splunk Enterprise versions below 10.4.2 and 10.2.6, a user who does not hold the "admin" or "power" Splunk role17d ago
CVE-2026-202587.1highsplunkIn Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 187d ago
CVE-2026-763307.1highsplunkIn Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an aut17d ago
CVE-2026-763337.1highsplunkIn Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role c17d ago
CVE-2026-201646.5mediumsplunkIn Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10178d ago
CVE-2026-201626.3mediumsplunkIn Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.9, and 9.3.9, and Splunk Cloud Platform versions below 10.178d ago
CVE-2026-201656.3mediumsplunkIn Splunk Enterprise versions below 10.2.1, 10.0.4, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10178d ago
CVE-2026-201665.4mediumsplunkIn Splunk Enterprise versions below 10.2.1 and 10.0.4, and Splunk Cloud Platform versions below 10.2.2510.5, 10.1.178d ago

Filter the full tracker by Splunk

Our coverage of Splunk

vulnerabilitycritical

Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities

The flaws could be exploited to execute arbitrary code, access sensitive information, and elevate privileges. The post Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities appeared first on SecurityWeek.

ai

What Working the Cisco Live SOC Taught Me About AI, Detection, and Response

A product manager shared insights gained from working at the Cisco Live Security Operations Center. The experience highlighted the effective use of artificial intelligence, Splunk Enterprise Security, and Extended Detection and Response (XDR) technologies for accelerating threat investigations and improving the development of security detection and response tools.