Multiple vulnerabilities in Splunk products (July 16, 2026)
Multiple vulnerabilities have been discovered in Splunk products. Some of them allow an attacker to cause a breach of data confidentiality, a breach of data integrity, and a cross-site request forgery (CSRF).
CSIRTS triage
- What
- Multiple vulnerabilities allow an attacker to breach data confidentiality, integrity, and perform cross-site request forgery.
- Who is affected
- Users of Splunk products are affected.
- Urgency
- Remediation is critical due to the potential for data breaches and integrity issues.
- Action
- Implement patches or mitigations as provided by Splunk.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Splunk products
Get an email when a new Splunk products advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0888/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-202960.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all scored CVEs.
- Low exploitation riskCVE-2026-82010.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all scored CVEs.
- Low exploitation riskCVE-2026-271430.54% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 42% of all scored CVEs.
- Low exploitation riskCVE-2026-82000.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all scored CVEs.
- Low exploitation riskCVE-2026-69140.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all scored CVEs.
- Low exploitation riskCVE-2026-240510.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all scored CVEs.
- Low exploitation riskCVE-2026-69150.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all scored CVEs.
- Low exploitation riskCVE-2026-271440.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all scored CVEs.
- Low exploitation riskCVE-2026-322830.62% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 46% of all scored CVEs.
- Low exploitation riskCVE-2026-202970.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[UPDATE] [medium] Golang Go: Multiple vulnerabilitiescert-bund
- medium[UPDATE] [medium] Red Hat Enterprise Linux (go-jose): Vulnerability allows denial of servicecert-bund
- high[UPDATE] [high] Golang Go: Multiple vulnerabilitiescert-bund
- medium[UPDATE] [medium] Golang Go: Multiple vulnerabilitiescert-bund
- medium[UPDATE] [medium] OpenSSL: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] Kiali for Red Hat OpenShift Service Mesh (Axios, Go, Follow-redirects): Multiple vulnerabiliti…cert-bund
- medium[NEW] [medium] Red Hat OpenShift Container Platform (fast-uri, OpenTelemetry-Go): Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Solaris third-party components: Multiple vulnerabilitiescert-bund
- medium[UPDATE] [medium] Red Hat Hardened Images RPMs: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Communications: Multiple vulnerabilitiescert-bund
- medium[UPDATE] [medium] Golang Go: Vulnerability allows Denial of Servicecert-bund
- high[UPDATE] [high] Splunk Splunk Enterprise: Multiple vulnerabilitiescert-bund
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans le noyau Linux d'Ubuntu (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux de SUSE (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux de Red Hat (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans Progress MOVEit Transfer (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux de Debian LTS (31 juillet 2026)2026-07-31