CRITICAL
Splunk Enterprise RCE Flaw Exploited Days After Disclosure
CISA disclosed that CVE-2026-20253, a critical Splunk Enterprise vulnerability, is being actively exploited just days after public disclosure. The flaw permits unauthenticated remote code execution. CISA has given federal agencies only three days to patch, underscoring the severity and urgency. Organizations running Splunk Enterprise should apply the available patch immediately rather than waiting for a routine maintenance window. No technical exploitation details (IOCs, targeted sectors) were included in current reporting.