Mmastodon TechnologyCybersecurity first seen 7 h ago, last 7 h ago, peak #9
Splunk patches critical unauthenticated RCE flaw in emergency release
Original: Splunk patched 17 CVEs yesterday. The one that matters most: CVE-2026-76268 (CVSS 9.1) — unauthenticated RCE via the Pat
Splunk has released fixes for 17 vulnerabilities, the most severe being CVE-2026-76268, rated 9.1. The flaw allows unauthenticated remote code execution through the Patroni REST API on search head cluster members, requiring no credentials or user interaction, only network access. Affected versions include 10.4.0–10.4.2 and 10.2.0–10.2.6. Security researchers are urging administrators to patch immediately given the low bar for exploitation.
Why now: A trivially exploitable, unauthenticated remote code execution bug in widely deployed Splunk software was just disclosed with patches available.
Evidence
- Splunk patched 17 CVEs yesterday. The one that matters most: CVE-2026-76268 (CVSS 9.1) — unauthenticated RCE via the Patroni REST API on search head cluster members. No credentials. No user interaction. Network access is enough. Affects 10.4.0–10.4.2 and 10.2.0–10.2.6. Not… · threataft@infosec.exchange · 2
API: https://socialmediatrends-api.osmike.com/v1/trends/1450081