Splunk has released a patch for a critical OS command injection vulnerability affecting its AI Toolkit, while Atlassian fixed numerous flaws in third-party dependencies across its products.

The Splunk vulnerability could allow authenticated attackers to inject arbitrary operating system commands, potentially leading to full system compromise. Atlassian's patches cover dozens of issues primarily in third-party libraries used by its software.

Technical details remain limited, but the Splunk flaw resides in the AI Toolkit component. Users of affected Atlassian products should review dependency lists for patched versions.

Splunk and Atlassian have both released updates. No evidence of active exploitation has been reported at this time.

The volume of fixes from Atlassian highlights the challenge of managing supply chain security for widely deployed enterprise software.