CISA flags Splunk Enterprise auth bypass under exploit
CISA added CVE-2026-20253, a missing authentication flaw in Splunk Enterprise, to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation.
CISA has added CVE-2026-20253 to its Known Exploited Vulnerabilities Catalog following confirmation of active exploitation in the wild. The vulnerability is a missing authentication for critical function issue affecting Splunk Enterprise, allowing attackers to bypass authentication controls. This vulnerability class is a frequent attack vector that poses significant risk to federal agencies and the broader enterprise.
Under Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch agencies are required to prioritize rapid remediation of KEV Catalog vulnerabilities on publicly exposed assets, particularly those that grant total control post-exploitation. The directive also establishes requirements for agencies to assess whether systems were compromised prior to patching. While the directive is mandatory only for federal agencies, CISA urges all organizations to adopt risk-based vulnerability management practices and prioritize remediation of cataloged vulnerabilities.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/alerts/2026/06/18/cisa-adds-one-known-exploited-vulnerability-catalog
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free