CVE-2026-76405Information Disclosure through Cleartext Storage in the App Key Value Store in the Splunk On-Call (VictorOps) app Exploitation status Not known exploited Fix YesAffected product S Splunk On-Call (VictorOps) Published 08/19/2026 Severity Medium CVE-2026-76404Remote Code Execution (RCE) through Deserialization of Untrusted Data in Splunk MCP Server app Exploitation status Not known exploited Fix YesAffected product S Splunk MCP Server app Published 08/19/2026 Severity Critical CVE-2026-76403Improper Certificate Validation through HTTP Event Collector Kerberos Authentication in Splunk Connect for Kafka Exploitation status Not known exploited Fix YesAffected product S Splunk Connect for Kafka Published 08/19/2026 Severity High CVE-2026-76402Server-Side Request Forgery (SSRF) through the REST API in Splunk Connect for Kafka Exploitation status Not known exploited Fix YesAffected product S Splunk Connect for Kafka Published 08/19/2026 Severity High CVE-2026-76401Regular Expression Denial of Service (DoS) through the REST API in Splunk Connect for Kafka Exploitation status Not known exploited Fix YesAffected product S Splunk Connect for Kafka Published 08/19/2026 Severity Medium CVE-2026-76400Denial of Service (DoS) through the REST API in Splunk Connect for Kafka Exploitation status Not known exploited Fix YesAffected product S Splunk Connect for Kafka Published 08/19/2026 Severity Medium CVE-2026-76399Incorrect Permission Assignment for Scheduled Searches in Splunk AI Toolkit Exploitation status Not known exploited Fix YesAffected product S Splunk AI Toolkit Published 08/19/2026 Severity High CVE-2026-76398Improper Access Control during Experiment History Deletion through the REST API in Splunk AI Toolkit Exploitation status Not known exploited Fix YesAffected product S Splunk AI Toolkit Published 08/19/2026 Severity Medium CVE-2026-76397Improper Access Control in Experiment History through the REST API in Splunk AI Toolkit Exploitation status Not known exploited Fix YesAffected product S Splunk AI Toolkit Published 08/19/2026 Severity High CVE-2026-76396Improper Access Control through Scheduled Searches in Splunk AI Toolkit Exploitation status Not known exploited Fix YesAffected product S Splunk AI Toolkit Published 08/19/2026 Severity High CVE-2026-76395Remote Code Execution (RCE) through Deserialization of Untrusted Data in the Model Loading REST API in Splunk AI Toolkit Exploitation status Not known exploited Fix YesAffected product S Splunk AI Toolkit Published 08/19/2026 Severity High CVE-2026-76394Missing Authorization in Container and Connection Management through the REST API in Splunk AI Toolkit Exploitation status Not known exploited Fix YesAffected product S Splunk AI Toolkit Published 08/19/2026 Severity High CVE-2026-76393Race Condition during Model Upload through the REST API in Splunk AI Toolkit Exploitation status Not known exploited Fix YesAffected product S Splunk AI Toolkit Published 08/19/2026 Severity Medium CVE-2026-76392Use of Hard-coded Credentials in Container Connections in Splunk AI Toolkit Exploitation status Not known exploited Fix YesAffected product S Splunk AI Toolkit Published 08/19/2026 Severity Medium CVE-2026-76391Improper Privilege Management through Agent Run History in Splunk AI Toolkit Exploitation status Not known exploited Fix YesAffected product S Splunk AI Toolkit Published 08/19/2026 Severity High CVE-2026-76390Information Disclosure through Splunk Web in Cisco Talos Intelligence for Enterprise Security Cloud Exploitation status Not known exploited Fix YesAffected product C Cisco Talos Intelligence for Enterprise Security Cloud Published 08/19/2026 Severity Medium CVE-2026-76389Server-Side Request Forgery (SSRF) through the REST API in Cisco Talos Intelligence for Enterprise Security Cloud Exploitation status Not known exploited Fix YesAffected product C Cisco Talos Intelligence for Enterprise Security Cloud Published 08/19/2026 Severity High CVE-2026-76388Privilege Escalation through Search Macro Permissions in Splunk Enterprise Security Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Security Published 08/19/2026 Severity High CVE-2026-76387SPL Injection through the REST API in Splunk Enterprise Security Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Security Published 08/19/2026 Severity High CVE-2026-76386Information Disclosure through Action Parameters in Zoom app for Splunk SOAR Exploitation status Not known exploited Fix YesAffected product Z Zoom app for Splunk SOAR Published 08/19/2026 Severity Medium CVE-2026-76385Information Disclosure through Action Parameters in Venafi app for Splunk SOAR Exploitation status Not known exploited Fix YesAffected product V Venafi app for Splunk SOAR Published 08/19/2026 Severity Medium CVE-2026-76384Information Disclosure through Action Parameters in Splunk Attack Analyzer Connector for Splunk SOAR Exploitation status Not known exploited Fix YesAffected product S Splunk Attack Analyzer Connector for Splunk SOAR Published 08/19/2026 Severity Medium CVE-2026-76383Information Disclosure through Action Parameters in RSA SecurID Authentication Manager app for Splunk SOAR Exploitation status Not known exploited Fix YesAffected product R RSA SecurID Authentication Manager app for Splunk SOAR Published 08/19/2026 Severity Medium CVE-2026-76382Information Disclosure through Action Parameters in Phantom app for Splunk SOAR Exploitation status Not known exploited Fix YesAffected product P Phantom app for Splunk SOAR Published 08/19/2026 Severity Medium CVE-2026-76381Information Disclosure through Action Parameters in MS Graph for Active Directory app for Splunk SOAR Exploitation status Not known exploited Fix YesAffected product M MS Graph for Active Directory app for Splunk SOAR Published 08/19/2026 Severity Medium CVE-2026-76380Information Disclosure through Action Parameters in CrowdStrike OAuth API app for Splunk SOAR Exploitation status Not known exploited Fix YesAffected product C CrowdStrike OAuth API app for Splunk SOAR Published 08/19/2026 Severity Medium CVE-2026-76379Information Disclosure through Action Parameters in Cisco Webex app for Splunk SOAR Exploitation status Not known exploited Fix YesAffected product C Cisco Webex app for Splunk SOAR Published 08/19/2026 Severity Medium CVE-2026-76378Information Disclosure through Action Parameters in Cisco Secure Malware Analytics app for Splunk SOAR Exploitation status Not known exploited Fix YesAffected product C Cisco Secure Malware Analytics app for Splunk SOAR Published 08/19/2026 Severity Medium CVE-2026-76377Information Disclosure through Action Parameters in Azure AD Graph app for Splunk SOAR Exploitation status Not known exploited Fix YesAffected product A Azure AD Graph app for Splunk SOAR Published 08/19/2026 Severity Medium CVE-2026-76376Information Disclosure through Action Parameters in AWS IAM app for Splunk SOAR Exploitation status Not known exploited Fix YesAffected product A AWS IAM app for Splunk SOAR Published 08/19/2026 Severity Medium CVE-2026-76375Information Disclosure through Environment Data Logging in AD LDAP app for Splunk SOAR Exploitation status Not known exploited Fix YesAffected product A AD LDAP app for Splunk SOAR Published 08/19/2026 Severity Medium CVE-2026-76374Information Disclosure through Sensitive Data Logging in AD LDAP app for Splunk SOAR Exploitation status Not known exploited Fix YesAffected product A AD LDAP app for Splunk SOAR Published 08/19/2026 Severity Medium CVE-2026-76373Filter Injection through Action Parameters in AD LDAP app for Splunk SOAR Exploitation status Not known exploited Fix YesAffected product A AD LDAP app for Splunk SOAR Published 08/19/2026 Severity Medium CVE-2026-76372Incorrect Permission Assignment through Safe Mode in Nmap Scanner for Splunk SOAR Exploitation status Not known exploited Fix YesAffected product N Nmap Scanner Published 08/19/2026 Severity Medium CVE-2026-76371Incorrect Permission Assignment through Safe Mode in FireAMP for Splunk SOAR Exploitation status Not known exploited Fix YesAffected product F FireAMP Published 08/19/2026 Severity Low CVE-2026-76370Information Disclosure through the REST API in Splunk SOAR Exploitation status Not known exploited Fix YesAffected product S Splunk SOAR Published 08/19/2026 Severity Medium CVE-2026-76369Path Traversal through Automation Broker in Splunk SOAR Exploitation status Not known exploited Fix YesAffected product S Splunk SOAR Published 08/19/2026 Severity Low CVE-2026-76368Missing Authorization through Playbooks in Splunk SOAR Exploitation status Not known exploited Fix YesAffected product S Splunk SOAR Published 08/19/2026 Severity Low CVE-2026-76367Stored Cross-Site Scripting (XSS) through Notes in Splunk SOAR Exploitation status Not known exploited Fix YesAffected product S Splunk SOAR Published 08/19/2026 Severity Medium CVE-2026-76366Information Disclosure through the REST API in Splunk SOAR Exploitation status Not known exploited Fix YesAffected product S Splunk SOAR Published 08/19/2026 Severity Medium CVE-2026-76365Structured Query Language (SQL) Injection through Custom Lists in Splunk SOAR Exploitation status Not known exploited Fix YesAffected product S Splunk SOAR Published 08/19/2026 Severity Medium CVE-2026-76364Structured Query Language (SQL) Injection through Custom Function Results in Splunk SOAR Exploitation status Not known exploited Fix YesAffected product S Splunk SOAR Published 08/19/2026 Severity Medium CVE-2026-76363Structured Query Language Injection through the REST API in Splunk SOAR Exploitation status Not known exploited Fix YesAffected product S Splunk SOAR Published 08/19/2026 Severity Medium CVE-2026-76362Improper Certificate Validation through CyberArk Vault Privileged Access Manager in Splunk SOAR Exploitation status Not known exploited Fix YesAffected product S Splunk SOAR Published 08/19/2026 Severity High CVE-2026-76361Server-Side Request Forgery (SSRF) through the Connectivity Check REST API in Splunk SOAR Exploitation status Not known exploited Fix YesAffected product S Splunk SOAR Published 08/19/2026 Severity Low CVE-2026-76360Information Disclosure through Missing Authorization in the Health REST API in Splunk SOAR Exploitation status Not known exploited Fix YesAffected product S Splunk SOAR Published 08/19/2026 Severity Medium CVE-2026-76359Path Traversal through Universal Forwarder Installer Archive Extraction in Splunk SOAR Exploitation status Not known exploited Fix YesAffected product S Splunk SOAR Published 08/19/2026 Severity Medium CVE-2026-76358Path Traversal through App Installation Tar Extraction in Splunk SOAR Exploitation status Not known exploited Fix YesAffected product S Splunk SOAR Published 08/19/2026 Severity Medium CVE-2026-76357Remote Code Execution (RCE) through Path Traversal in the REST API in Splunk SOAR Exploitation status Not known exploited Fix YesAffected product S Splunk SOAR Published 08/19/2026 Severity High CVE-2026-76356Authentication Bypass through IP Address Spoofing in the Automation Broker in Splunk SOAR Exploitation status Not known exploited Fix YesAffected product S Splunk SOAR Published 08/19/2026 Severity High CVE-2026-76355Unauthenticated Information Disclosure through an Edge Processor Service Endpoint in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity High CVE-2026-76354Path Traversal through Search Head Clustering in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity High CVE-2026-76353Path Traversal through Knowledge Bundle Replication in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity Medium CVE-2026-76352Improper Authorization through the REST API in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity High CVE-2026-76351Server-Side Request Forgery (SSRF) through the Report Notification REST API in Splunk Secure Gateway Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity High CVE-2026-76350Improper Privilege Management through PDF Attachments for Email Alert Actions in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity High CVE-2026-76349SPL Injection through Splunk Web Form Tokens in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity Medium CVE-2026-76348Missing Authorization in Search Head Cluster Member Controls in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity Low CVE-2026-76347Server-Side Request Forgery (SSRF) through the Report Notifications REST API in Splunk Secure Gateway Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity Medium CVE-2026-76346Stored Cross-Site Scripting (XSS) through Splunk Web Dashboard Sparkline Format Options in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity Medium CVE-2026-76345Remote Code Execution (RCE) through the REST API in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity Medium CVE-2026-76344Path Traversal through the Search Dispatch REST API in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity High CVE-2026-76343Structured Query Language (SQL) Injection through the REST API in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity Medium CVE-2026-76342Risky Commands Safeguards Bypass through Splunk Web in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity Medium CVE-2026-76341Risky Commands Safeguards Bypass through Table Editor Dataset Initial Data in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity Medium CVE-2026-76340Missing Authorization for Reloading Token-Signing Keys through the REST API in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity Medium CVE-2026-76339SPL Injection through the geostats Command in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity Medium CVE-2026-76338Improper Authentication through REST API Distributed Search Token Requests in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity High CVE-2026-76337Path Traversal through Splunk Web Static File Serving in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity Medium CVE-2026-76336Improper Access Control through the REST API in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity High CVE-2026-76335Remote Code Execution (RCE) through Splunk Web Manager Configuration in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity High CVE-2026-76334SPL Injection through Dashboard Studio Workflow Actions in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity Medium CVE-2026-76333Stored Cross-Site Scripting (XSS) through Dashboard Studio Workflow Actions in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity High CVE-2026-76332SPL Injection through Splunk Web in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity High CVE-2026-76331SPL Injection through the REST API in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity High CVE-2026-76330SPL Injection through Monitoring Console Forwarder Filters in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity High CVE-2026-76329SPL Injection through Monitoring Console Dashboard Inputs in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity Medium CVE-2026-76328SPL Injection through Splunk Web in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity Medium CVE-2026-76327SPL Injection through Splunk Web in Splunk Secure Gateway Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity Medium CVE-2026-76326Stored Cross-Site Scripting through Dashboard Sparkline Tooltip Options in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity Medium CVE-2026-76325Stored Cross-Site Scripting (XSS) through Splunk Web in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity High CVE-2026-76324Stored Cross-Site Scripting (XSS) in Splunk Web Tours in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity Medium CVE-2026-76323SPL Risky Command Safeguards Bypass through the Job Details Dashboard in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity Medium CVE-2026-76322SPL Injection through Dashboard Studio Search Query Options in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity Medium CVE-2026-76321SPL Injection through Nearby Event Searches in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity High CVE-2026-76320SPL Injection through Cross-Site Request Forgery (CSRF) in the Event Type Builder in Splunk Web for Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity Medium CVE-2026-76319Remote Code Execution (RCE) through Federated Search in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity High CVE-2026-76318Stored Cross-Site Scripting (XSS) through Splunk Web in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity Medium CVE-2026-76317Path Traversal through the Lookup Configuration REST API in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity High CVE-2026-76316Stored SPL Injection through Deployment Server Broker Registration in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity High CVE-2026-76315Code Injection through Splunk Web Manager Configuration in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity High CVE-2026-76314Remote Code Execution (RCE) through Splunk Web Manager Configuration in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity High CVE-2026-76313Remote Code Execution (RCE) through the REST API in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity High CVE-2026-76312Improper Access Control through Embedded Reports in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity Critical CVE-2026-76311Improper Access Control in Embedded Report Dispatch Archives in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity Critical CVE-2026-76310Improper Access Control through Embedded Report REST API Requests in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity Critical CVE-2026-76309Structured Query Language (SQL) Injection through the REST API in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity Medium CVE-2026-76263Improper Access Control through the REST API in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity Medium CVE-2026-76262Exposure of Sensitive Information to an Unauthorized Actor through the REST API in Splunk Enterprise Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity High CVE-2026-76261Insecure Default Access Control List through the REST API in Splunk Secure Gateway Exploitation status Not known exploited Fix YesAffected product S Splunk Enterprise Published 08/19/2026 Severity Medium