- Sources: Splunk security advisory SVD-2026-0808
- Summary: Splunk published SVD-2026-0808 on 2026-08-19, covering 17 CVEs with an overall rating of critical and a maximum CVSS of 9.1. Two of the seventeen are remote code execution through deserialization of untrusted data: CVE-2026-76404 in the Splunk MCP Server app 1.2, affecting versions below 1.2.1 and fixed in 1.2.1, and CVE-2026-76395 in the Splunk AI Toolkit, affecting 6.0 below 6.0.1 and 5.7 below 6.0.0 and fixed in 6.0.1 and 6.0.0. The advisory's product status table also lists Cisco Talos Intelligence for Enterprise Security Cloud 1.0 below 1.0.3, Splunk Connect for Kafka 2.2 below 2.2.7, and Splunk On-Call (VictorOps) 1.0 below 1.0.43, with each affected boundary equal to its fixed version. The 9.1 is not attributed to a named CVE here, because the advisory page lists scores and CVE ids as parallel unordered sets and the mapping was not resolvable from it.
- Why it matters: Two of the seventeen are remote code execution through deserialization of untrusted data, one of them in the Splunk MCP Server app, which is the component teams point coding agents at.
- Follow-up: Resolve which CVE carries the 9.1 score.
send feedback on this story