SIEM and log analytics
Splunk advisories: every record the registers tie to its products
In one line
29 advisories are attributed to Splunk products in this record, covering October 2023 to July 2026, and 1 of them appears in the CISA catalogue of known exploited vulnerabilities. A further 39 register entries mention Splunk without naming one of its products as affected, and are excluded rather than counted. Each entry below links to the register that published it.
Attributed
29
tied to a named product
Known exploited
1
in the CISA catalogue
Rated critical
1
by the register
Last checked
Jul 17, 2026
sources re-queried
Why this list is shorter than a CVE mirror
The registers are searched by keyword, so a search for a company name returns advisories that merely mention it. A mirror publishes those. This page does not: an entry appears only when the register itself ties it to a product of Splunk, through a reference on the vendor's own domain, the vendor named as the assigning authority, or the affected product list naming it.
39 entries did not clear that bar and are not shown. That is the difference, and it is deliberate: a page that lists another company's vulnerability under this heading is wrong in the way that matters most.
29 of the 29 records carry a CVSS base score from the register. Where none is published, none is shown, and no score is estimated.
The full list, most recently exploited and most recent first
Records held by several registers are folded into one entry with a link to each, so the same vulnerability is not counted twice. Entries listed in the CISA catalogue of known exploited vulnerabilities are shown first, because that is the one flag on this page that changes what a reader should do next.
- CVE-2026-20253criticalCVSS 9.8Known exploitedJun 18, 2026
Splunk Enterprise Missing Authentication for Critical Function Vulnerability
- WID-SEC-2026-2370highCVSS 8.3Jul 16, 2026
Affected products: Splunk Splunk Enterprise
- WID-SEC-2026-1877highCVSS 9.8Jun 15, 2026
Affected products: Splunk Splunk Enterprise
- WID-SEC-2026-1876lowCVSS 4.3Jun 11, 2026
Affected products: Splunk SOAR
- WID-SEC-2026-1618highCVSS 9.1May 21, 2026
Affected products: Splunk Splunk Enterprise
- WID-SEC-2026-1139mediumCVSS 7.1Apr 16, 2026
Affected products: Splunk Splunk Enterprise
- WID-SEC-2026-0696mediumCVSS 7.2Mar 12, 2026
Affected products: Splunk Splunk Enterprise
- WID-SEC-2026-0457mediumCVSS 7.7Feb 19, 2026
Affected products: Splunk Splunk Enterprise
- WID-SEC-2024-3674highCVSS 8.8Jan 26, 2026
Affected products: Splunk Splunk Enterprise, Atlassian Bitbucket, Dell Data Protection Advisor
- WID-SEC-2024-0049highCVSS 9.8Jan 26, 2026
Affected products: Splunk Splunk Enterprise, Atlassian Bitbucket, Dell Data Protection Advisor
- WID-SEC-2023-1350mediumCVSS 7.3Jan 26, 2026
Affected products: IBM DB2, SUSE Linux, Splunk Splunk Enterprise, Atlassian Confluence
- WID-SEC-2025-2735highCVSS 8.0Dec 04, 2025
Affected products: Splunk Splunk Enterprise
- WID-SEC-2025-2683lowCVSS 2.7Nov 27, 2025
Affected products: Splunk Splunk Enterprise
- WID-SEC-2023-0395highCVSS 8.1Nov 19, 2025
Affected products: Splunk Splunk Enterprise, Atlassian Bitbucket
- WID-SEC-2023-2229highCVSS 9.8Nov 19, 2025
Affected products: SUSE Linux, Oracle Linux, Splunk Splunk Enterprise, Atlassian Confluence
- WID-SEC-2025-0647highCVSS 8.0Nov 19, 2025
Affected products: Splunk Splunk Enterprise, Atlassian Jira, Atlassian Bitbucket
- WID-SEC-2025-2588lowCVSS 3.5Nov 13, 2025
Affected products: Splunk Splunk Enterprise
- WID-SEC-2025-2188mediumCVSS 7.5Oct 02, 2025
Affected products: Splunk Splunk Enterprise
- WID-SEC-2025-1473mediumCVSS 6.8Oct 01, 2025
Affected products: Splunk Splunk Enterprise, Absolute Secure Access
- WID-SEC-2023-2964highCVSS 8.0Jul 25, 2025
Affected products: IBM AIX, IBM VIOS, Amazon Linux 2, Red Hat Enterprise Linux
- WID-SEC-2024-1494highCVSS 8.8Jul 07, 2025
Affected products: Debian Linux, Splunk Splunk Enterprise
- WID-SEC-2025-1219highCVSS 8.0Jun 03, 2025
Affected products: Splunk Splunk Enterprise
- WID-SEC-2025-0108mediumCVSS 6.5Jan 16, 2025
Affected products: Splunk Splunk Enterprise
- WID-SEC-2024-0732highCVSS 8.1Nov 28, 2024
Affected products: Splunk Splunk Enterprise
- WID-SEC-2024-3054mediumCVSS 7.5Oct 31, 2024
Affected products: Splunk Splunk Enterprise
- WID-SEC-2024-3168highCVSS 8.8Oct 15, 2024
Affected products: Splunk Splunk Enterprise
- WID-SEC-2024-0249mediumCVSS 6.8Jan 31, 2024
Affected products: Splunk Splunk Enterprise
- WID-SEC-2024-0174mediumCVSS 7.5Jan 23, 2024
Affected products: Splunk Splunk Enterprise
- WID-SEC-2023-1346highCVSS 8.8Oct 10, 2023
Affected products: Splunk Splunk Enterprise
Which registers contributed
| Register | Operated by | Entries | Latest |
|---|---|---|---|
| European Vulnerability Database | ENISA, European Union | 40 | Jul 15, 2026 |
| CERT-Bund security advisories | BSI, Federal Republic of Germany | 28 | Jul 16, 2026 |
| Known Exploited Vulnerabilities catalogue | CISA, United States | 1 | Jun 18, 2026 |
The entry counts here are the raw register totals for Splunk, before attribution. They are larger than the list above for exactly that reason.
Questions this page answers
How many vulnerabilities does Splunk have?
29 advisories in this record are tied by a register to a product of Splunk. That is not the same as the number of vulnerabilities the products contain, and no public source knows that number. It is the count of what has been found, disclosed and published, which depends on how much the products are examined and how openly the vendor discloses.
Are any Splunk vulnerabilities being actively exploited?
1 of the 29 records here appears in the CISA catalogue of known exploited vulnerabilities, which lists flaws with confirmed exploitation in the wild. They are shown first in the list above. Whether any of them affects your deployment depends on the versions and components you run.
Why does this page show fewer CVEs for Splunk than other sites?
Because a keyword search for a company name returns advisories about other companies' products that mention it in passing, and this page excludes those. 39 register entries name Splunk without naming one of its products as affected. A mirror that lists them produces a longer page and a wrong number.
Where do the Splunk advisories on this page come from?
From European Vulnerability Database (ENISA, European Union); CERT-Bund security advisories (BSI, Federal Republic of Germany); Known Exploited Vulnerabilities catalogue (CISA, United States). Every entry links back to the register that published it, and carries the date that register states. Where the same vulnerability is held by several registers it is shown once with a link to each, rather than counted twice.
Does a long advisory list mean Splunk is insecure?
No. A register records what researchers found and what the vendor disclosed, so a widely deployed product with a working disclosure process accumulates more entries than one nobody examines. A short list can equally mean a small install base or a vendor that publishes little. This page reports the record and does not rate the vendor, because whether this is acceptable depends on your risk appetite, your compliance scope and the alternatives you are weighing.
A list of advisories is not a risk assessment
What matters is which of these touch the components you actually run, in the configuration you actually run them in, and whether that is acceptable next to the alternatives on your shortlist. DecisionOS reads the same pool against the criteria of a real decision and produces a memo that holds up in front of a board and an auditor.
The full Splunk record, including sources and open questions
