poslední zpráva · zachyceno
SPOJENO AI EPSS 0.00 (nejvyšší)
Security Hardening in Splunk Enterprise - September/October 2026
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8, CVEs: CVE-2026-76281, CVE-2026-76282, CVE-2026-76283, CVE-2026-76284, CVE-2026-76285, Summary: Splunk addressed multiple internally identified vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The vulnerabilities are grouped by Common Weakness Enumeration (CWE), with one Common Vulnerabilities and Exposures (CVE) identifier assigned to each group.
Splunk FI NL CA IT FR US
CVE v události 22
| CVE | hodnocení | KEV | EPSS |
|---|---|---|---|
| CVE-2026-76264 | 4.3 3.1 · cisco | – | 0.00 |
| CVE-2026-76265 | 6.5 3.1 · cisco | – | 0.00 |
| CVE-2026-76266 | 7.7 3.1 · cisco | – | 0.00 |
| CVE-2026-76267 | 4.3 3.1 · cisco | – | 0.00 |
| CVE-2026-76268 | 9.8 3.1 · cisco | – | 0.00 |
| CVE-2026-76269 | 6.5 3.1 · cisco | – | 0.00 |
| CVE-2026-76270 | 6.5 3.1 · cisco | – | 0.00 |
| CVE-2026-76271 | 6.5 3.1 · cisco | – | 0.00 |
| CVE-2026-76272 | 4.3 3.1 · cisco | – | 0.00 |
| CVE-2026-76273 | 4.3 3.1 · cisco | – | 0.00 |
| CVE-2026-76274 | 6.5 3.1 · cisco | – | 0.00 |
| CVE-2026-76275 | 4.3 3.1 · cisco | – | 0.00 |
| CVE-2026-76276 | 4.3 3.1 · cisco | – | 0.00 |
| CVE-2026-76277 | 4.1 3.1 · cisco | – | 0.00 |
| CVE-2026-76278 | 4.3 3.1 · cisco | – | 0.00 |
| CVE-2026-76279 | 4.3 3.1 · cisco | – | 0.00 |
| CVE-2026-76280 | 6.3 3.1 · cisco | – | 0.00 |
| CVE-2026-76281 | 5.3 3.1 · CISA-ADP | – | 0.00 |
| CVE-2026-76282 | 8.8 3.1 · CISA-ADP | – | 0.00 |
| CVE-2026-76283 | 7.6 3.1 · CISA-ADP | – | 0.00 |
| CVE-2026-76284 | 9.8 3.1 · CISA-ADP | – | 0.00 |
| CVE-2026-76285 | – | – | 0.00 |
Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 9.8.
Jak se o tom psalo 7
-
· zachyceno · NCSC-FI FI nadpis události
Security Hardening in Splunk Enterprise - September/October 2026
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8, CVEs: CVE-2026-76281, CVE-2026-76282, CVE-2026-76283, CVE-2026-76284, CVE-2026-76285, Summary: Splunk addressed multiple internally identified vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The vulnerabilities are grouped by Common Weakness Enumeration (CWE), with one Common Vulnerabilities and Exposures (CVE) identifier assigned to each group.
-
· NCSC-NL NL
NCSC-2026-0412 [1.00] [M/H] Kwetsbaarheden verholpen in Splunk Enterprise
Splunk heeft meerdere kwetsbaarheden verholpen in Splunk Enterprise. De kwetsbaarheden betreffen verschillende versies van Splunk Enterprise en omvatten onder andere onvoldoende autorisatiecontroles in REST API endpoints, waardoor niet-bevoegde gebruikers toegang kunnen krijgen tot geprivilegieerde functionaliteit of gevoelige gegevens. Sommige kwetsbaarheden maken het mogelijk voor gebruikers zonder admin- of power-rollen om configuratiewijzigingen door te voeren, payloads te laten…
-
· Cyber Centre Kanada CA
Splunk security advisory (AV26-1018)
Serial number: AV26-1018 Date: October 8, 2026 As of October 7, 2026, Splunk is affected by vulnerabilities in the following products: Splunk Enterprise Prior to 10.0.10 Prior to 10.2.7 Prior to 10.4.3 Prior to 9.4.15 Splunk MCP Server Prior to 1.2.1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Security Vulnerabilities in Splunk Enterprise - September/October 2026 - SVD-2026-1001 Security…
-
· CSIRT Itálie (ACN) IT
Rilevate vulnerabilità in prodotti Splunk
Rilevate molteplici nuove vulnerabilità in prodotti Splunk, di cui 3 con gravità "critica" e 3 con gravità "alta" in Splunk Enterprise. Tali vulnerabilità, qualora sfruttate, potrebbero consentire ad un utente malintenzionato, in determinate condizioni, di eseguire codice arbitrario, eludere meccanismi di sicurezza ed elevare i propri privilegi sui sistemi interessati.
-
· zachyceno · CERT-FR – avis FR
Multiples vulnérabilités dans les produits Splunk (08 octobre 2026)
De multiples vulnérabilités ont été découvertes dans les produits Splunk. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et une atteinte à la confidentialité des données.
-
· zachyceno · Splunk Advisories US
SVD-2026-1001: Security Vulnerabilities in Splunk Enterprise - September/October 2026
Splunk addressed multiple vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. See CVE Details for vulnerability-specific affected versions, additional remediation, acknowledgments, and workarounds.
-
· zachyceno · Splunk Advisories US
SVD-2026-1002: Security Hardening in Splunk Enterprise - September/October 2026
Splunk addressed multiple internally identified vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The vulnerabilities are grouped by Common Weakness Enumeration (CWE), with one Common Vulnerabilities and Exposures (CVE) identifier assigned to each group. See Details for more information.