Splunk security advisory (AV26-1018)
Canada's Cyber Centre urges patches for vulnerabilities in Splunk Enterprise and Splunk MCP Server.
On October 8, 2026, the Canadian Centre for Cyber Security issued advisory AV26-1018 on Splunk vulnerabilities known as of October 7. Affected Splunk Enterprise versions are those before 10.0.10, 10.2.7, 10.4.3, and 9.4.15, and Splunk MCP Server before 1.2.1. The centre points administrators to Splunk notices SVD-2026-1001 and SVD-2026-1004 and recommends applying available updates. The advisory does not report active exploitation.
- Advisory AV26-1018 covers Splunk Enterprise and Splunk MCP Server.
- Enterprise builds before 10.0.10, 10.2.7, 10.4.3, and 9.4.15 are affected.
- Splunk MCP Server is affected before version 1.2.1.
- The bulletin cites SVD-2026-1001 and SVD-2026-1004 and reports no exploitation.
Full article87 words · extracted from cyber.gc.ca · click to collapse
Serial number: AV26-1018
Date: October 8, 2026
As of October 7, 2026, Splunk is affected by vulnerabilities in the following products:
- Splunk Enterprise
- Prior to 10.0.10
- Prior to 10.2.7
- Prior to 10.4.3
- Prior to 9.4.15
- Splunk MCP Server
- Prior to 1.2.1
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/splunk-security-advisory-av26-1018