Third-Party Package Updates in Splunk Universal Forwarder - August 2026

Advisory ID: SVD-2026-0803

CVE ID: 

Published: 2026-08-19

Last Update: 2026-08-19

Description

Splunk remedied common vulnerabilities and exposures (CVEs) in Third Party Packages in Splunk Universal Forwarder versions 10.4.2, 10.2.6, 10.0.9, 9.4.14, and higher.

PackageRemediationCVESeverity
OpenSSL1Upgraded OpenSSL to versions 1.0.2zq and 3.5.7MultipleMedium

1 Upgraded OpenSSL to version 1.0.2zq to remedy CVE-2026-28388, CVE-2026-28389, and CVE-2026-28390 at $SPLUNK_HOME/lib/libcrypto.so.1.0.0 and $SPLUNK_HOME/lib/libssl.so.1.0.0 in Splunk Universal Forwarder versions 10.0.x, 10.2.x, 10.4.x, 9.3.x, and 9.4.x. Upgraded OpenSSL to version 3.5.7 at $SPLUNK_HOME/bin/openssl to remedy CVE-2026-31789 and CVE-2026-31790 for Splunk Universal Forwarder versions 10.4.2, 10.2.6, and 10.0.9.

Solution

Upgrade Splunk Universal Forwarder to versions 10.4.2, 10.2.6, 10.0.9, 9.4.14, or higher.

Product Status

ProductBase VersionAffected VersionFix Version
Splunk Universal Forwarder10.410.4.0 to 10.4.110.4.2
Splunk Universal Forwarder10.210.2.0 to 10.2.510.2.6
Splunk Universal Forwarder10.010.0.0 to 10.0.810.0.9
Splunk Universal Forwarder9.49.4.0 to 9.4.139.4.14

Severity

For the CVEs in this list, Splunk adopted the vendor’s severity rating or the National Vulnerability Database (NVD) common vulnerability scoring system (CVSS) rating, as available.