
Splunk's three Critical Enterprise CVEs: one is explained, two are only a weakness class and a score Splunk published five advisories on 7 October listing 83 distinct CVEs. Of those, 23 are flaws in Splunk's own code, and three of the 23 score Critical: CVE-2026-76268 (9.8), CVE-2026-76281 (9.8) and CVE-2026-76284 (9.0). Only the first comes with an explanation. 🧮 CVE-2026-76268: an unauthenticated user with network access to the Patroni REST API on a search head cluster member could run operating-system commands, on builds below 10.4.3 and 10.2.7. Splunk's mitigation is to turn off the PostgreSQL sidecar if Edge Processor, OpAmp and SPL2 pipelines are unused. The other two sit in an advisory titled "Security Hardening" and are a weakness class and a score: no component, precondition or mitigation, all four branches affected. 🔍 Not stated: exploitation, in either direction, on any of the five pages. None of the 83 CVEs is in CISA's catalogue, whose latest version predates the advisories. The affected ranges end at the August fix builds on every branch, 49 days later (derived). A public repository claims proof-of-concept code for CVE-2026-76268; we did not open it and it is unverified. The MCP Server flaw, CVE-2026-76286 (5.3), is a token leak, not prompt injection. ⚖️ First fixed builds: 10.4.3, 10.2.7, 10.0.10 and 9.4.15; MCP Server 1.2.1. Cyber Essentials v3.3 gives 14 days for critical or high fixes; the NCSC gives 5 days for internet-facing software, 12 October at the latest. Splunk added its June exploitation statement eight days after publishing, so re-read its pages before you close the change. 🔑 If one of your search head cluster members were compromised tonight, which record of it would exist on a system the attacker could not reach, and who would be reading that record? Full briefing: https://www.pk-sharma.com/briefing/splunk-enterprise-three-critical-cves-only-one-explained #Splunk #SIEM #VulnerabilityManagement #CVE #PatchManagement #CyberEssentials #NCSC #MCP #SOC #InfoSec #CyberSecurity #CISO #BlueTeam #UKTech

