VORANT. Threat Intelligence Sign in Get the full feed

CISA flags Splunk Enterprise auth bypass under exploit

high vulnerability government-national

CISA added CVE-2026-20253, a missing authentication flaw in Splunk Enterprise, to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation.

CISA has added CVE-2026-20253 to its Known Exploited Vulnerabilities Catalog following confirmation of active exploitation in the wild. The vulnerability is a missing authentication for critical function issue affecting Splunk Enterprise, allowing attackers to bypass authentication controls. This vulnerability class is a frequent attack vector that poses significant risk to federal agencies and the broader enterprise.

Under Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch agencies are required to prioritize rapid remediation of KEV Catalog vulnerabilities on publicly exposed assets, particularly those that grant total control post-exploitation. The directive also establishes requirements for agencies to assess whether systems were compromised prior to patching. While the directive is mandatory only for federal agencies, CISA urges all organizations to adopt risk-based vulnerability management practices and prioritize remediation of cataloged vulnerabilities.

Mentioned in this report

Vulnerabilities CVE-2026-20253KEV

Source reporting: https://www.cisa.gov/news-events/alerts/2026/06/18/cisa-adds-one-known-exploited-vulnerability-catalog

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free