Splunk security advisory (AV26-838)

Serial Number: AV26-838
Date: August 21, 2026

As of August 19, 2026, Splunk is affected by vulnerabilities in the following products:

  • Cisco Talos Intelligence for Enterprise Security Cloud
    • Prior to 1.0.3
  • Splunk Enterprise
    • Prior to 10.0.9
    • Prior to 10.2.6
    • Prior to 10.4.1
    • Prior to 10.4.2
    • Prior to 9.4.14
  • Splunk MCP Server app
    • Prior to 1.2.1
  • Splunk Universal Forwarder
    • Prior to 10.4.2
    • Prior to 10.2.6
    • Prior to 10.0.9
    • Prior to 9.4.14
  • Splunk SOAR
    • Prior to 8.6.0
  • Splunk SOAR Connectors
    • Multiple versions and models
  • Splunk Enterprise Security
    • Prior to 8.6.1
  • Splunk Apps and Add-ons
    • Multiple versions and models

The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.

Date modified: