Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication
2026-06-14T13:24:07Z•bad5bc90adf3403f4b3973f6f21780d83ada85114149c7f35d724ce349eefe34
agentjackingai-agent-attacksaur-hijackbitlocker-bypasscisa-keveBPF-rootkitfortinetinfostealerinterpol-takedownlangfloworacle-peoplesoftransomwareremote-code-executionsplunksupply-chainunauthenticated-rce
What happened
This collection of The Hacker News stories highlights multiple high‑impact cyber incidents and disclosures. Headline: Splunk Enterprise fixes a critical unauthenticated vulnerability (CVE-2026-20253, CVSS 9.8) that could allow arbitrary file operations and remote code execution. Other notable items include: Oracle PeopleSoft zero-day exploitation by ShinyHunters (CVE-2026-35273); Fortinet FortiSandbox command injection (CVE-2026-25089); Langflow path traversal being actively exploited (CVE-2026-5027); Cisco Catalyst SD‑WAN Manager flaw added to CISA KEV (CVE-2026-20245); a large Arch AUR hijac
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- bad5bc90adf3403f4b3973f6f21780d83ada85114149c7f35d724ce349eefe34
- Enrichment time
- 2026-06-14T13:24:07Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.