MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 9 h ago, last 9 h ago, peak #9

Splunk patches critical unauthenticated RCE flaw in emergency release

Original: Splunk patched 17 CVEs yesterday. The one that matters most: CVE-2026-76268 (CVSS 9.1) — unauthenticated RCE via the Pat

Splunk has released fixes for 17 vulnerabilities, the most severe being CVE-2026-76268, rated 9.1. The flaw allows unauthenticated remote code execution through the Patroni REST API on search head cluster members, requiring no credentials or user interaction, only network access. Affected versions include 10.4.0–10.4.2 and 10.2.0–10.2.6. Security researchers are urging administrators to patch immediately given the low bar for exploitation.

Why now: A trivially exploitable, unauthenticated remote code execution bug in widely deployed Splunk software was just disclosed with patches available.

SplunkCVE-2026-76268Patroni

Open on mastodon →

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/1450081