CISA Adds the First-Ever Splunk Flaw to Its KEV Catalog, an Unauthenticated File-Write Bug in a PostgreSQL Sidecar Now Exploited in the Wild
CVE-2026-20253, a CVSS 9.8 missing-authentication flaw in Splunk Enterprise's PostgreSQL sidecar, became the first Splunk bug on CISA's KEV list, with federal agencies ordered to patch by June 21.