search
Patroni
Trends
- 1Splunk patches critical unauthenticated RCE flaw in emergency release●Splunk patched 17 CVEs yesterday. The one that matters most: CVE-2026-76268 (CVSS 9.1) — unauthenticated RCE via the Pat
Splunk has released fixes for 17 vulnerabilities, the most severe being CVE-2026-76268, rated 9.1. The flaw allows unauthenticated remote code execution through the Patroni REST API on search head cluster members, requiring no credentials or user interaction, only network access. Affected versions include 10.4.0–10.4.2 and 10.2.0–10.2.6. Security researchers are urging administrators to patch immediately given the low bar for exploitation.
- 2Critical Splunk flaw lets attackers run OS commands unauthenticated●An unauthenticated attacker with network access to a Splunk search head cluster member can execute arbitrary OS commands
A critical vulnerability, tracked as CVE-2026-76268 with a CVSS score of 9.1, affects Splunk Enterprise search head cluster members running versions 10.4.x and 10.2.x. An attacker with network access can execute arbitrary operating system commands without credentials or user interaction. The flaw is tied to Patroni, a component bundled with Splunk Enterprise.
- 3Critical Splunk vulnerability CVE-2026-76268 earns maximum severity score●🔴 CVE-2026-76268 - Critical (9.8) In Splunk Enterprise versions below 10.4.3 and 10.2.7, an unauthenticated user with ne
A critical vulnerability, CVE-2026-76268, has been disclosed in Splunk Enterprise versions below 10.4.3 and 10.2.7. The flaw, scored 9.8, allows an unauthenticated attacker with network access to the Patroni REST API on a search head cluster member to execute arbitrary code. Security teams are urged to patch affected deployments immediately.