<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — Splunk</title><description>Actively exploited vulnerabilities affecting Splunk products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/splunk.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-20253 — Splunk Enterprise Missing Authentication for Critical Function Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-20253</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-20253</guid><description>This flaw in Splunk Enterprise allows an unauthenticated attacker to create or truncate arbitrary files by targeting an exposed PostgreSQL sidecar service endpoint — no login required. For organizations running Splunk, this means an outsider could corrupt, destroy, or overwrite critical data or configuration files, potentially disrupting security monitoring operations entirely. Because Splunk is commonly used as a central security and logging platform, compromising it can blind defenders at exactly the wrong moment.</description><pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate><category>Splunk</category><category>Enterprise</category></item></channel></rss>