Splunk CVE-2026-20253: a 72-hour triage and remediation runbook
CVE-2026-20253 is the first Splunk vulnerability ever added to CISA's KEV catalog: an unauthenticated RCE via the PostgreSQL sidecar. Here is the version matrix, the temporary workaround, and an hour-by-hour SOC runbook.