🚨 CVE-2026-20253 is not yet in CISA KEV.
But KEVIntel honeypots are already seeing sustained attacker activity targeting Splunk Enterprise.
- 80 exploitation attempts
- 17 attacker IPs
- 8 countries
If Splunk is exposed in your environment, this should be on the radar.
Full telemetry in the comment reply.