MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 10 h ago, last 10 h ago, peak #11

Critical Splunk flaw lets attackers run OS commands unauthenticated

Original: An unauthenticated attacker with network access to a Splunk search head cluster member can execute arbitrary OS commands

A critical vulnerability, tracked as CVE-2026-76268 with a CVSS score of 9.1, affects Splunk Enterprise search head cluster members running versions 10.4.x and 10.2.x. An attacker with network access can execute arbitrary operating system commands without credentials or user interaction. The flaw is tied to Patroni, a component bundled with Splunk Enterprise.

Why now: Security teams are urgently discussing a newly disclosed unauthenticated remote code execution flaw in widely deployed Splunk infrastructure.

SplunkCVE-2026-76268Patroni

Open on mastodon →

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/1450083