Splunk is a software platform designed to search, analyze, and visualize machine-generated data from various sources, including websites, applications, sensors, and devices.
In 2024, Splunk was acquired by Cisco, which aims to leverage Splunk’s capabilities to enhance digital resilience across its customer base.
Splunk has released security updates to address multiple critical vulnerabilities in Splunk Enterprise that could allow attackers to execute arbitrary code remotely.
The flaws discovered by both internal and external security researchers affect Splunk Enterprise versions 9.0.x, 9.1.x, and 9.2.x.
The company urges users to update their systems immediately to mitigate potential risks.
"Is Your System Under Attack? Try Cynet XDR: Automated Detection & Response for Endpoints, Networks, & Users!"- Free Demo
Among the most severe issues patched are:
Additionally, several cross-site scripting (XSS) vulnerabilities were addressed that could allow attackers to execute malicious JavaScript in users’ browsers.
The recent updates from Splunk, which were rolled out on Monday, also target medium-severity vulnerabilities that impact both the Enterprise and Cloud Platform products.
Splunk strongly recommends users upgrade to the latest patched versions:
The company noted that Splunk Cloud Platform instances are also being patched and monitored.
These vulnerabilities highlight the importance of promptly applying security updates, especially for critical enterprise software like Splunk, which often processes sensitive data. Organizations using affected versions of Splunk Enterprise should prioritize upgrading to mitigate the risk of exploitation.
Are you from SOC/DFIR Teams? - Sign up for a free ANY.RUN account! to Analyse Advanced Malware Files
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…