惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

有赞技术团队
有赞技术团队
Martin Fowler
Martin Fowler
N
Netflix TechBlog - Medium
WordPress大学
WordPress大学
罗磊的独立博客
H
Help Net Security
MongoDB | Blog
MongoDB | Blog
A
About on SuperTechFans
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
D
Docker
云风的 BLOG
云风的 BLOG
Microsoft Security Blog
Microsoft Security Blog
Blog — PlanetScale
Blog — PlanetScale
P
Proofpoint News Feed
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
I
InfoQ
J
Java Code Geeks
博客园 - 聂微东
大猫的无限游戏
大猫的无限游戏
Engineering at Meta
Engineering at Meta
美团技术团队
小众软件
小众软件
Stack Overflow Blog
Stack Overflow Blog
C
Check Point Blog

Cyber Security News

AIRecon: AI-Powered Penetration Testing Tool with Kali Linux Sandbox Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code - Update Now! UNC3753 Uses Screen-Sharing Sessions and RMM Tools to Exfiltrate Sensitive Legal Data New OnionDrop Loader Campaign Uses gainmsg C2 to Deliver LegionLoader Payloads ClickFix Campaign Uses EtherHiding and GULoader to Infect Windows Users via Fake CAPTCHA Ghostwriter Hackers Abuse Gmail Admin-Themed Emails to Steal Credentials and 2FA Codes The Half-Life of Threat Intelligence: When Does an IOC Stop Being Useful? Critical Fortinet FortiSandbox Vulnerabilities Actively Exploited in Attacks Aembit Extends IAM for Agentic AI to Microsoft Copilot Studio India Temporarily Bans Telegram Messenger Over Medical Exam Fraud Microsoft 365 Device Code Phishing Campaign Bypasses Password Theft With Legitimate Login Flow AppViewX Launches Agent Identity Security to Govern Agents for the AI and Quantum Era Hackers Weaponize Microsoft Teams Relay to Hide Ransomware Traffic Developer laptops are the credential store attackers are picking through in 2026, GitGuardian announces Endpoint Protection Interlock and Rhysida Ransomware Operations Share Supper Backdoor and Malware Codebase Novo Nordisk Confirms Cyber Attack — Hackers Accessed Patient Medical Data and Internal AI Assets Russian and Chinese Influence Actors Use AI to Evade Bot Detection and Mimic Human Behavior Microsoft Teams Analyze the Wi-Fi Hotspot Data Connected to an Employee’s Device PRC-Nexus Hackers Exploit REDCap Servers to Spy on US Medical Research Institutions Infinite Campus Data Breach Exposes 137,000 Users Personal Details OptinMonster Plugin Hack Exposes 1.2 Million Wordpress Sites to Cyberattack Ransomware Ecosystem Consolidates Around LockBit Alumni, Qilin, Hyflock, and The Gentlemen Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns LiteSpeed cPanel Plugin 0-Day Vulnerability Actively Exploited in the Wild Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks Nearly 14,000 SimpleHelp Servers Exposed Amid Critical Authentication Bypass Disclosure Microsoft Site Showing Warning Following Certificate Expiry DPAPISnoop Tool Extracts CREDHIST Hashes for Offline Windows Credential Recovery SHADOWBYT3$ Allegedly Claim Breach of Nintendo, Stealing Sensitive Data Anthropic Updated Privacy Policy to Include Identity Verification for Claude Users
CISA Warns of Splunk Enterprise Critical Function Vulnera...
Abinaya · 2026-06-19 · via Cyber Security News

CISA has issued a high-priority alert warning organizations about a critical vulnerability in Splunk Enterprise that is actively being exploited in the wild.

The flaw, tracked as CVE-2026-20253, has been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog, signaling immediate risk to enterprise environments.

According to CISA, the vulnerability stems from a missing authentication mechanism for a critical function within Splunk Enterprise. Specifically, the issue affects a PostgreSQL sidecar service endpoint, which unauthenticated attackers can abuse.

Successful exploitation enables threat actors to create or truncate arbitrary files on affected systems, potentially causing severe operational disruption or further compromise.

The flaw is categorized under CWE-306 (Missing Authentication for Critical Function), a class of vulnerabilities that continues to pose significant risks due to inadequate access controls on sensitive operations.

Splunk Enterprise Function Vulnerability Exploit

In this case, attackers do not require valid credentials to exploit the issue, dramatically increasing its severity and making internet-exposed instances particularly vulnerable.

Although no ransomware campaigns have been confirmed, CISA has emphasized that the vulnerability poses a high risk due to its ease of exploitation and potential impact.

Attackers could leverage arbitrary file creation or deletion capabilities to manipulate system behavior, disrupt logging mechanisms, or stage additional payloads.

CISA added CVE-2026-20253 to its KEV catalog on June 18, 2026, and has mandated remediation under Binding Operational Directive (BOD) 26-04.

Federal agencies are required to address the vulnerability by June 21, 2026, highlighting the urgency of the threat.

The directive prioritizes rapid patching of actively exploited vulnerabilities that pose a significant risk to federal networks. Security teams are strongly advised to follow Splunk’s vendor-provided mitigation guidance.

Organizations should immediately assess whether their Splunk Enterprise deployments are exposed to the internet and apply necessary updates or mitigations.

If patches are unavailable or cannot be applied in time, CISA recommends discontinuing use of the affected product until it can be secured.

Additionally, CISA has urged stakeholders to follow its Forensics Triage Requirements to detect potential compromise. This includes reviewing logs, monitoring unusual file activity, and identifying unauthorized access attempts to the PostgreSQL service endpoint.

An example attack scenario could involve an unauthenticated attacker sending crafted requests to the vulnerable endpoint to overwrite critical configuration or log files. This could turn off security monitoring or enable further lateral movement within the network.

Organizations using Splunk Enterprise should treat this vulnerability as a top priority. Immediate action, including patching, exposure assessment, and forensic validation, is essential to prevent exploitation and minimize potential damage.

Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

Abinaya

Abinayahttps://cybersecuritynews.com/

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.