← nejvýznamnější zprávy · všechny zprávy

poslední zpráva · zachyceno

SPOJENO AI EPSS 0.00 (nejvyšší)

Security Hardening in Splunk Enterprise - September/October 2026

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8, CVEs: CVE-2026-76281, CVE-2026-76282, CVE-2026-76283, CVE-2026-76284, CVE-2026-76285, Summary: Splunk addressed multiple internally identified vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The vulnerabilities are grouped by Common Weakness Enumeration (CWE), with one Common Vulnerabilities and Exposures (CVE) identifier assigned to each group.

Číst originál na NCSC-FI →

7 zpráv z 6 zdrojů · první · zachyceno CZ · EN/orig

Splunk FI NL CA IT FR US

tg: zranitelnost tg: novinka v produktu

CVE v události 22

CVEhodnoceníKEVEPSS
CVE-2026-76264 4.3 3.1 · cisco – 0.00
CVE-2026-76265 6.5 3.1 · cisco – 0.00
CVE-2026-76266 7.7 3.1 · cisco – 0.00
CVE-2026-76267 4.3 3.1 · cisco – 0.00
CVE-2026-76268 9.8 3.1 · cisco – 0.00
CVE-2026-76269 6.5 3.1 · cisco – 0.00
CVE-2026-76270 6.5 3.1 · cisco – 0.00
CVE-2026-76271 6.5 3.1 · cisco – 0.00
CVE-2026-76272 4.3 3.1 · cisco – 0.00
CVE-2026-76273 4.3 3.1 · cisco – 0.00
CVE-2026-76274 6.5 3.1 · cisco – 0.00
CVE-2026-76275 4.3 3.1 · cisco – 0.00
CVE-2026-76276 4.3 3.1 · cisco – 0.00
CVE-2026-76277 4.1 3.1 · cisco – 0.00
CVE-2026-76278 4.3 3.1 · cisco – 0.00
CVE-2026-76279 4.3 3.1 · cisco – 0.00
CVE-2026-76280 6.3 3.1 · cisco – 0.00
CVE-2026-76281 5.3 3.1 · CISA-ADP – 0.00
CVE-2026-76282 8.8 3.1 · CISA-ADP – 0.00
CVE-2026-76283 7.6 3.1 · CISA-ADP – 0.00
CVE-2026-76284 9.8 3.1 · CISA-ADP – 0.00
CVE-2026-76285 – – 0.00

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 9.8.

Jak se o tom psalo 7

  1. · zachyceno · NCSC-FI FI nadpis události

    Security Hardening in Splunk Enterprise - September/October 2026

    Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8, CVEs: CVE-2026-76281, CVE-2026-76282, CVE-2026-76283, CVE-2026-76284, CVE-2026-76285, Summary: Splunk addressed multiple internally identified vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The vulnerabilities are grouped by Common Weakness Enumeration (CWE), with one Common Vulnerabilities and Exposures (CVE) identifier assigned to each group.

  2. · NCSC-NL NL

    NCSC-2026-0412 [1.00] [M/H] Kwetsbaarheden verholpen in Splunk Enterprise

    Splunk heeft meerdere kwetsbaarheden verholpen in Splunk Enterprise. De kwetsbaarheden betreffen verschillende versies van Splunk Enterprise en omvatten onder andere onvoldoende autorisatiecontroles in REST API endpoints, waardoor niet-bevoegde gebruikers toegang kunnen krijgen tot geprivilegieerde functionaliteit of gevoelige gegevens. Sommige kwetsbaarheden maken het mogelijk voor gebruikers zonder admin- of power-rollen om configuratiewijzigingen door te voeren, payloads te laten…

  3. · Cyber Centre Kanada CA

    Splunk security advisory (AV26-1018)

    Serial number: AV26-1018 Date: October 8, 2026 As of October 7, 2026, Splunk is affected by vulnerabilities in the following products: Splunk Enterprise Prior to 10.0.10 Prior to 10.2.7 Prior to 10.4.3 Prior to 9.4.15 Splunk MCP Server Prior to 1.2.1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Security Vulnerabilities in Splunk Enterprise - September/October 2026 - SVD-2026-1001 Security…

  4. · CSIRT Itálie (ACN) IT

    Rilevate vulnerabilità in prodotti Splunk

    Rilevate molteplici nuove vulnerabilità in prodotti Splunk, di cui 3 con gravità "critica" e 3 con gravità "alta" in Splunk Enterprise. Tali vulnerabilità, qualora sfruttate, potrebbero consentire ad un utente malintenzionato, in determinate condizioni, di eseguire codice arbitrario, eludere meccanismi di sicurezza ed elevare i propri privilegi sui sistemi interessati.

  5. · zachyceno · CERT-FR – avis FR

    Multiples vulnérabilités dans les produits Splunk (08 octobre 2026)

    De multiples vulnérabilités ont été découvertes dans les produits Splunk. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et une atteinte à la confidentialité des données.

  6. · zachyceno · Splunk Advisories US

    SVD-2026-1001: Security Vulnerabilities in Splunk Enterprise - September/October 2026

    Splunk addressed multiple vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. See CVE Details for vulnerability-specific affected versions, additional remediation, acknowledgments, and workarounds.

  7. · zachyceno · Splunk Advisories US

    SVD-2026-1002: Security Hardening in Splunk Enterprise - September/October 2026

    Splunk addressed multiple internally identified vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The vulnerabilities are grouped by Common Weakness Enumeration (CWE), with one Common Vulnerabilities and Exposures (CVE) identifier assigned to each group. See Details for more information.