Splunk Patches Critical 9.8 Flaw Allowing Unauthenticated Remote Command Execution

Splunk has released security updates to fix a critical Splunk Enterprise vulnerability that could let an attacker run operating system commands without logging in. Tracked as CVE-2026-76268, the flaw carries a CVSS v3.1 score of 9.8 and was disclosed on October 7, 2026. It affects the Patroni REST API on search head cluster members, where […]

This article has been indexed from Cyber Security News

Read the original article: