CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Splunk security advisory (AV26-838)

unknown
Serial Number: AV26-838 Date: August 21, 2026 As of August 19, 2026, Splunk is affected by vulnerabilities in the following products: Cisco Talos Intelligence for Enterprise Security Cloud Prior to 1.0.3 Splunk Enterprise Prior to 10.0.9 Prior to 10.2.6 Prior to 10.4.1 Prior to 10.4.2 Prior to 9.4.14 Splunk MCP Server app Prior to 1.2.1 Splunk Universal Forwarder Prior to 10.4.2 Prior to 10.2.6 Prior to 10.0.9 Prior to 9.4.14 Splunk SOAR Prior to 8.6.0 Splunk SOAR Connectors Multiple versions and models Splunk Enterprise Security Prior to 8.6.1 Splunk Apps and Add-ons Multiple versions and models The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. Splunk Security Advisories

CSIRTS triage

vendor: SplunkOtheraffected: Splunk Enterprise prior to 10.0.9, 10.2.6, 10.4.1, 10.4.2, 9.4.14; Universal Forwarder prior to 10.4.2, 10.2.6, 10.0.9, 9.4.14; SOAR prior to 8.6.0; Enterprise Security prior to 8.6.1; and other produ
What
Multiple vulnerabilities affect Splunk products including Enterprise, Universal Forwarder, SOAR, and Enterprise Security.
Who is affected
Splunk Enterprise, Universal Forwarder, SOAR, Enterprise Security, and MCP Server app deployments across multiple versions.
Urgency
Moderate: no active exploitation reported; severity unspecified pending advisory review.
Action
Apply security updates to all affected Splunk products by upgrading to the specified minimum versions.

AI-assisted analysis generated from the source advisory — verify against the original.

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
unknown
Published
2026-08-21
Exploitation
Not in CISA KEV at last sync

Original advisory: https://cyber.gc.ca/en/alerts-advisories/splunk-security-advisory-av26-838

More from Canadian Centre for Cyber Security