Security Briefing | June 19, 2026 - Splunk RCE Actively Exploited, FortiBleed Hits 86K Devices, Klue OAuth Breach Exposes Salesforce Data
CISA orders federal agencies to patch an actively exploited unauthenticated RCE in Splunk Enterprise (CVE-2026-20253) by June 21, 2026. The FortiBleed credential leak grows to approximately 86,000 Fortinet devices, nearly half of all internet-accessible firewalls and VPNs. A supply chain breach of Klue's OAuth integration exposes Salesforce CRM data across multiple organizations, including cybersecurity firms Huntress and Recorded Future.
By EACA Summit Content Team

1. CISA Urges Patching of Actively Exploited Splunk Enterprise RCE Vulnerability
CISA has added CVE-2026-20253, a critical unauthenticated remote code execution vulnerability in Splunk Enterprise, to its Known Exploited Vulnerabilities catalog. Federal agencies are required to patch by June 21, 2026. The vulnerability was disclosed days ago and is already being exploited in attacks.
Verified Facts
- CVE-2026-20253 is a critical unauthenticated RCE in Splunk Enterprise
- CISA added the vulnerability to its KEV catalog on June 18, 2026
- Federal agencies must patch by June 21, 2026
- Exploitation in the wild has been confirmed
Evidence
- CVE-2026-20253
- CISA KEV catalog entry
- BleepingComputer article
Impact
Organizations using Splunk Enterprise are at immediate risk of remote compromise. Defenders must prioritize patching and monitor for exploitation attempts.
Confidence Level: High
BleepingComputer | SecurityWeek
2. FortiBleed Leak Exposes 86,000 Fortinet Device Credentials; CISA Warns

A large-scale credential theft campaign dubbed 'FortiBleed' has compromised approximately 86,000 Fortinet firewall and VPN credentials, affecting nearly half of internet-accessible Fortinet devices. CISA has urged Fortinet customers to secure their devices immediately.
Verified Facts
- Approximately 86,000 Fortinet device credentials were leaked
- The leak affected roughly half of internet-accessible Fortinet firewalls and VPNs
- CISA issued a warning urging Fortinet customers to secure devices
- The campaign is dubbed 'FortiBleed'
Evidence
- CISA advisory
- BleepingComputer article
- SecurityWeek article
Impact
Organizations using Fortinet devices must immediately rotate credentials, enforce MFA, and review access logs. The scale of the leak poses a significant risk of network compromise.
Confidence Level: High
BleepingComputer | SecurityWeek
3. Klue OAuth Breach Leads to Salesforce Data Theft Across Multiple Organizations
Salesforce disabled the Klue Battlecards app integration after an OAuth token abuse incident on June 11, 2026, linked to the 'Icarus' threat actor. The breach allowed attackers to steal Salesforce CRM data from multiple Klue customers, including cybersecurity firms Huntress and Recorded Future.
Verified Facts
- Salesforce disabled Klue app integration on June 11, 2026
- The breach involved OAuth token abuse by the 'Icarus' threat actor
- Multiple Klue customers had Salesforce data exfiltrated
- Cybersecurity firms Huntress and Recorded Future were among the impacted organizations
Evidence
- Salesforce advisory
- The Hacker News article
- BleepingComputer article
Impact
This supply chain attack highlights the risk of third-party OAuth integrations. Organizations using Klue or similar apps should review connected OAuth tokens and monitor for unauthorized access to Salesforce data.
Confidence Level: High
The Hacker News | BleepingComputer | SecurityWeek
All intelligence in this briefing is independently verified. Confidence levels reflect source reliability and corroboration at time of publishing.



