Vulnerabilities — Page 28

Vulnerabilities

Oracle's June 2026 CPU: 245 Patches Across Communications, EBS, and Enterprise Manager

Oracle's second monthly Critical Patch Update ships a significant fix load. If you're running EBS or Enterprise Manager in AWS or on-prem, your change window just got scheduled for you.

2 min read
Vulnerabilities

CISA Flags Joomla Content Editor Bug as Actively Exploited; CVSS 10.0

CVE-2026-48907 in Widget Factory's JCE extension hands attackers arbitrary file actions on unpatched Joomla sites. Federal agencies get the standard three weeks.

2 min read
Vulnerabilities

Three FortiSandbox Bugs Under Active Exploitation, Including a 9.1 Path Traversal

Threat intel firm flags in-the-wild abuse of CVE-2026-39813, CVE-2026-39808 and CVE-2026-25089 within a 24-hour window.

2 min read
Vulnerabilities

Cisco's SD-WAN Manager Has a Write-to-Root Problem — and Attackers Found It First

CVE-2026-20262 lets an authenticated attacker overwrite arbitrary files on Cisco Catalyst SD-WAN Manager, with a clear path to root. No workaround exists. Exploitation is already underway.

2 min read
Vulnerabilities

Twenty-Five Orgs Are Quietly Triaging Open-Source Vulns Before You Hear About Them

A coalition called Athena is building shared infrastructure to find, fix, and harden OSS projects in the window between discovery and public disclosure.

2 min read
Vulnerabilities

CISA Adds LiteSpeed cPanel Plugin Bug to KEV After In-the-Wild Exploitation

CVE-2026-54420 (CVSS 8.5) lets attackers escalate to root on hosts running the LiteSpeed cPanel plugin. Federal agencies have until June 18, 2026 to patch.

3 min read
Vulnerabilities

Cisco Patches Catalyst SD-WAN Manager Bug Already Seeing In-the-Wild Abuse

CVE-2026-20262 lets an authenticated remote user write files on the appliance. Cisco confirms exploitation. Severity is rated medium, but the access it enables is not.

2 min read
Vulnerabilities

Weekly Recap: Chrome Zero-Day, UniFi RCE, macOS Stealers, and a VPN Auth Bypass

Another seven days of rented phishing kits, AI-themed lures, and forgotten software paying out as initial access.

3 min read
Vulnerabilities

Palo Alto Confirms In-the-Wild Abuse of GlobalProtect Auth Bypass (CVE-2026-0257)

An unknown actor is exploiting a 7.8-rated authentication bypass in PAN-OS portals and gateways to slip past GlobalProtect logins.

2 min read
Vulnerabilities

Splunk Patches CVE-2026-20253, a 9.8-Rated Unauthenticated RCE in Enterprise

The advisory covers Splunk Enterprise builds below 10.2.4 and 10.0.7, with fixed versions now available.

2 min read
Vulnerabilities

GreatXML's BitLocker Bypass Claim Falls Short — For Now

A pseudonymous researcher dropped an alleged WinRE-based BitLocker exploit days after Patch Tuesday. A respected vulnerability analyst couldn't replicate it. The researcher is already hunting a fix.

3 min read
Vulnerabilities

ShinyHunters Rode a PeopleSoft Zero-Day Into University Networks

A CVSS 9.8 RCE flaw in Oracle PeopleSoft gave UNC6240 a two-week head start before Oracle even confirmed the bug existed.

2 min read
Vulnerabilities

CISA Gives Agencies 72 Hours on Ivanti Sentry Bug Under New Emergency Directive

BOD 26-04 sets a sharper clock for actively exploited flaws. First target: an Ivanti Sentry vulnerability already in attackers' hands.

2 min read
Vulnerabilities

Langflow Path Traversal Flaw CVE-2026-5027 Hits CISA's Exploited List

An unauthenticated write-anywhere bug in the open-source AI builder is being abused in the wild, per VulnCheck telemetry, raising fresh questions for federal users bound by BOD 22-01 patch deadlines.

2 min read
Vulnerabilities

GreatXML Bypasses BitLocker Through a Trusted Recovery Path

A researcher's four-hour weekend project shows how Windows' own offline scan plumbing can sidestep full-disk encryption.

3 min read
© 2026 Threat Vectr