Multiple vulnerabilities in Splunk products (20 August 2026)
Multiple vulnerabilities have been discovered in Splunk products. Some of them allow an attacker to cause arbitrary code execution remotely, privilege escalation and breach of data confidentiality.
CSIRTS triage
- What
- Multiple vulnerabilities in Splunk products allow remote code execution, privilege escalation, and data confidentiality breach.
- Who is affected
- Organizations using various Splunk products across the portfolio.
- Urgency
- High priority; RCE and privilege escalation represent critical security risks with no indication of exploitation difficulty.
- Action
- Identify affected Splunk products and apply vendor patches for the eight CVEs listed.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1056/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-260070.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-134730.71% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 51% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-763490.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-325970.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-319580.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-763290.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-64740.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-400870.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-64720.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-341801.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 60% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [high] NGINX Open Source and NGINX Plus: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] NGINX and NGINX Plus: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] OpenSSL: Multiple Vulnerabilitiescert-bund
- high[UPDATE] [high] PostgreSQL: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] Golang Go: Multiple vulnerabilitiescert-bund
- unknownNCSC-2026-0322 [1.00] [M/H] Vulnerabilities fixed in Splunk Enterprise by Splunkncsc-nl
- unknownNCSC-2026-0321 [1.00] [M/H] Multiple vulnerabilities fixed in IBM AIX and IBM PowerVM VIOSncsc-nl
- unknownexploitedMultiple vulnerabilities in IBM products (August 21, 2026)cert-fr-avis
- high[UPDATE] [high] cURL: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] Red Hat OpenShift Container Platform (gRPC-Go): Vulnerability allows bypassing security measur…cert-bund
- high[NEW] [high] Splunk SOAR: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Splunk Splunk Enterprise: Multiple vulnerabilitiescert-bund
Recent advisories for Splunk products
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownSplunk Products Multiple Vulnerabilitieshkcert · 2026-08-20
- unknownMultiple vulnerabilities in Splunk products (July 16, 2026)cert-fr-avis · 2026-07-16
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Keycloak (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in Cisco IOS XE (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in LibreNMS (August 24, 2026)2026-08-24
- unknownMultiple vulnerabilities in Metabase (August 24, 2026)2026-08-24
- unknownVulnerability in SPIP (August 21, 2026)2026-08-21