Splunk vendor intelligence
Splunk Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting Splunk products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 3
- Known exploited vulnerabilities affecting Splunk products
- In CISA KEV
- 1
- Records also listed in the official catalog
- Beyond CISA KEV
- 2
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 1
- Splunk KEV with sensor-observed exploitation activity
The catalog gap matters for Splunk exposure
Two of the three exploited Splunk CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss two-thirds of this vendor portfolio.
- 33%
- Covered by CISA
- 67%
- Beyond CISA
- 2
- Product families
Attested Splunk CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2026-20253
Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise |
Splunk Enterprise | Confirmed | In CISA | 15 Jun 2026 |
|
CVE-2018-11409
Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json to a query, as demonstrated... |
Splunk | High | Beyond CISA | 07 May 2026 |
|
CVE-2024-36991
Path Traversal on the “/modules/messaging/“ endpoint in Splunk Enterprise on Windows |
Splunk Enterprise | High | Beyond CISA | 01 Jul 2024 |
No Splunk CVEs match this search or filter.
Showing 3 of 3 Splunk known exploited vulnerabilities.
Recurring weakness patterns
Exposure, missing authentication for critical function, and path traversal: '.../...//' account for three mapped occurrences across this Splunk KEV portfolio.
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.