# Splunk vulnerabilities & exploitation

**CISA KEV**

> As of 2026-10-10, Threadlinqs tracks 33 Splunk CVEs, 2 in the CISA Known Exploited Vulnerabilities catalog, linked to 9 tracked threat campaigns and 2 named threat actors.

**Data as of:** 2026-10-10

## Exploitation timeline

Threadlinqs has recorded 33 Splunk CVEs published between 2026-02-15 and 2026-10-15. The busiest month was 2026-10 (23 new CVEs). 2 of them (6%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 33 of 33 tracked Splunk CVEs.

- [CVE-2026-20253](https://intel.threadlinqs.com/cve/CVE-2026-20253) — CRITICAL 9.8 · KEV · EPSS 88.2% · 2026-06-10
- [CVE-2026-20265](https://intel.threadlinqs.com/cve/CVE-2026-20265) — CRITICAL 9.8 · KEV · EPSS 0.2% · 2026-06-17
- [CVE-2026-20251](https://intel.threadlinqs.com/cve/CVE-2026-20251) — HIGH 8.8 · EPSS 32.2% · 2026-06-10
- [CVE-2026-20139](https://intel.threadlinqs.com/cve/CVE-2026-20139) — MEDIUM 4.3 · EPSS 5.2% · 2026-02-18
- [CVE-2026-20266](https://intel.threadlinqs.com/cve/CVE-2026-20266) — CRITICAL 9.1 · EPSS 0.6% · 2026-06-17
- [CVE-2026-76268](https://intel.threadlinqs.com/cve/CVE-2026-76268) — CRITICAL 9.8 · EPSS 0.4% · 2026-10-07
- [CVE-2026-20138](https://intel.threadlinqs.com/cve/CVE-2026-20138) — MEDIUM 6.8 · EPSS 0.3% · 2026-02-18
- [CVE-2026-76282](https://intel.threadlinqs.com/cve/CVE-2026-76282) — HIGH 8.8 · EPSS 0.3% · 2026-10-07
- [CVE-2026-76271](https://intel.threadlinqs.com/cve/CVE-2026-76271) — MEDIUM 6.5 · EPSS 0.3% · 2026-10-07
- [CVE-2026-76274](https://intel.threadlinqs.com/cve/CVE-2026-76274) — MEDIUM 6.5 · EPSS 0.3% · 2026-10-07
- [CVE-2026-76270](https://intel.threadlinqs.com/cve/CVE-2026-76270) — MEDIUM 6.5 · EPSS 0.2% · 2026-10-07
- [CVE-2026-20137](https://intel.threadlinqs.com/cve/CVE-2026-20137) — LOW 3.5 · EPSS 0.2% · 2026-02-18
- [CVE-2026-76265](https://intel.threadlinqs.com/cve/CVE-2026-76265) — MEDIUM 6.5 · EPSS 0.2% · 2026-10-07
- [CVE-2026-76269](https://intel.threadlinqs.com/cve/CVE-2026-76269) — MEDIUM 6.5 · EPSS 0.2% · 2026-10-07
- [CVE-2026-76281](https://intel.threadlinqs.com/cve/CVE-2026-76281) — MEDIUM 5.3 · EPSS 0.2% · 2026-10-07
- [CVE-2026-76275](https://intel.threadlinqs.com/cve/CVE-2026-76275) — MEDIUM 4.3 · EPSS 0.2% · 2026-10-07
- [CVE-2026-76283](https://intel.threadlinqs.com/cve/CVE-2026-76283) — HIGH 7.6 · EPSS 0.2% · 2026-10-07
- [CVE-2026-76277](https://intel.threadlinqs.com/cve/CVE-2026-76277) — MEDIUM 4.1 · EPSS 0.2% · 2026-10-07
- [CVE-2026-76276](https://intel.threadlinqs.com/cve/CVE-2026-76276) — MEDIUM 4.3 · EPSS 0.2% · 2026-10-07
- [CVE-2026-76286](https://intel.threadlinqs.com/cve/CVE-2026-76286) — MEDIUM 5.3 · EPSS 0.2% · 2026-10-07
- [CVE-2026-76264](https://intel.threadlinqs.com/cve/CVE-2026-76264) — MEDIUM 4.3 · EPSS 0.2% · 2026-10-07
- [CVE-2026-76280](https://intel.threadlinqs.com/cve/CVE-2026-76280) — MEDIUM 6.3 · EPSS 0.2% · 2026-10-07
- [CVE-2026-76272](https://intel.threadlinqs.com/cve/CVE-2026-76272) — MEDIUM 4.3 · EPSS 0.2% · 2026-10-07
- [CVE-2026-76267](https://intel.threadlinqs.com/cve/CVE-2026-76267) — MEDIUM 4.3 · EPSS 0.2% · 2026-10-07
- [CVE-2026-76273](https://intel.threadlinqs.com/cve/CVE-2026-76273) — MEDIUM 4.3 · EPSS 0.2% · 2026-10-07
- [CVE-2026-76279](https://intel.threadlinqs.com/cve/CVE-2026-76279) — MEDIUM 4.3 · EPSS 0.2% · 2026-10-07
- [CVE-2026-76278](https://intel.threadlinqs.com/cve/CVE-2026-76278) — MEDIUM 4.3 · EPSS 0.2% · 2026-10-07
- [CVE-2026-76284](https://intel.threadlinqs.com/cve/CVE-2026-76284) — EPSS 0.2% · 2026-10-07
- [CVE-2026-76285](https://intel.threadlinqs.com/cve/CVE-2026-76285) — EPSS 0.1% · 2026-10-07
- [CVE-2026-76266](https://intel.threadlinqs.com/cve/CVE-2026-76266) — HIGH 7.7 · EPSS 0.1% · 2026-10-07
- [CVE-2026-20296](https://intel.threadlinqs.com/cve/CVE-2026-20296) — HIGH 8.3 · 2026-07-15
- [CVE-2026-20297](https://intel.threadlinqs.com/cve/CVE-2026-20297) — HIGH 7.2 · 2026-07-15
- [CVE-2026-20298](https://intel.threadlinqs.com/cve/CVE-2026-20298) — MEDIUM 5.3 · 2026-07-15

## Products affected

Threadlinqs normalises CPE and CNA product records across all 33 CVEs; 5 distinct Splunk products are affected. The most frequently affected:

- Enterprise — 30 CVEs
- Cloud Platform — 6 CVEs
- Secure Gateway — 4 CVEs
- AI Toolkit — 2 CVEs
- MCP Server — 1 CVE

## Threat activity

9 tracked threat campaigns reference Splunk products or exploit Splunk CVEs:

- [Splunk Enterprise and Secure Gateway: 22 vulnerabilities patched (SVD-2026-1001/1002), including critical CVE-2026-76268 (Patroni REST API missing authentication, CVSS 9.8) and CVE-2026-76281 (listed 9.8 in advisory)](https://intel.threadlinqs.com/threat/TL-2026-3110) — CRITICAL — 2026-10-09
- [SonicWall SMA1000 Pre-Auth SSRF (CVE-2026-102255, CVSS 10.0) and Critical Splunk Enterprise Vulnerabilities (CVE-2026-76268, CVE-2026-76281, CVE-2026-76284) Patched](https://intel.threadlinqs.com/threat/TL-2026-3176) — CRITICAL — 2026-10-08
- [Multiple Splunk Enterprise Vulnerabilities Enable Path Traversal and Information Disclosure (CVE-2026-20296, CVE-2026-20297, CVE-2026-20298)](https://intel.threadlinqs.com/threat/TL-2026-1409) — HIGH — 2026-07-16
- [CVE-2026-20251: Splunk Secure Gateway jsonpickle Deserialization RCE with Public PoC](https://intel.threadlinqs.com/threat/TL-2026-1203) — HIGH — 2026-07-11
- [Splunk AI Toolkit OS Command Injection in btool Configuration Helper (CVE-2026-20266)](https://intel.threadlinqs.com/threat/TL-2026-0877) — CRITICAL — 2026-06-19
- [CVE-2026-20253: Unauthenticated Pre-Auth RCE in Splunk Enterprise PostgreSQL Sidecar Service (SVD-2026-0603)](https://intel.threadlinqs.com/threat/TL-2026-0786) — CRITICAL — 2026-06-13
- [CVE-2026-20253: Critical Unauthenticated Remote Code Execution in Splunk Enterprise via PostgreSQL Sidecar Service](https://intel.threadlinqs.com/threat/TL-2026-1103) — CRITICAL — 2026-06-10
- [Cisco Webex Services Critical Improper Certificate Validation Flaw (CVE-2026-20184) Enables Man-in-the-Middle Against Cloud Meeting Traffic](https://intel.threadlinqs.com/threat/TL-2026-0376) — CRITICAL — 2026-04-16
- [Interlock Ransomware Exploits Cisco FMC Zero-Day (CVE-2026-20265) Amid March 2026 CVE Surge](https://intel.threadlinqs.com/threat/TL-2026-0356) — CRITICAL — 2026-04-13

## Threat actors targeting Splunk

Named threat actors attributed to campaigns that involve Splunk products or CVEs, with the number of linked campaigns:

- [Interlock](https://intel.threadlinqs.com/actor/Interlock) — 1 campaign
- [Interlock Ransomware Group](https://intel.threadlinqs.com/actor/Interlock%20Ransomware%20Group) — 1 campaign

## How to prioritise Splunk patching

This order follows the data Threadlinqs holds for Splunk, not a generic severity checklist:

- 2 of 33 Splunk CVEs (6%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with [CVE-2026-20253](https://intel.threadlinqs.com/cve/CVE-2026-20253), [CVE-2026-20265](https://intel.threadlinqs.com/cve/CVE-2026-20265).
- Outside KEV, the highest EPSS scores are [CVE-2026-20251](https://intel.threadlinqs.com/cve/CVE-2026-20251) (32.2%), [CVE-2026-20139](https://intel.threadlinqs.com/cve/CVE-2026-20139) (5.2%), [CVE-2026-20266](https://intel.threadlinqs.com/cve/CVE-2026-20266) (0.6%).
- 4 CVEs score Critical and 6 High on CVSS v3 (maximum 9.8, average 6.3); sequence these after KEV and high-EPSS items.
- 2 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-10 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/splunk
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
