Splunk security advisory (AV26-1018)
Canada's Cyber Centre urges patches for vulnerabilities in Splunk Enterprise and Splunk MCP Server.
On October 8, 2026, the Canadian Centre for Cyber Security issued advisory AV26-1018 on Splunk vulnerabilities known as of October 7. Affected Splunk Enterprise versions are those before 10.0.10, 10.2.7, 10.4.3, and 9.4.15, and Splunk MCP Server before 1.2.1. The centre points administrators to Splunk notices SVD-2026-1001 and SVD-2026-1004 and recommends applying available updates. The advisory does not report active exploitation.