Vulnerabilities — Page 28

Oracle's June 2026 CPU: 245 Patches Across Communications, EBS, and Enterprise Manager
Oracle's second monthly Critical Patch Update ships a significant fix load. If you're running EBS or Enterprise Manager in AWS or on-prem, your change window just got scheduled for you.

CISA Flags Joomla Content Editor Bug as Actively Exploited; CVSS 10.0
CVE-2026-48907 in Widget Factory's JCE extension hands attackers arbitrary file actions on unpatched Joomla sites. Federal agencies get the standard three weeks.

Three FortiSandbox Bugs Under Active Exploitation, Including a 9.1 Path Traversal
Threat intel firm flags in-the-wild abuse of CVE-2026-39813, CVE-2026-39808 and CVE-2026-25089 within a 24-hour window.

Cisco's SD-WAN Manager Has a Write-to-Root Problem — and Attackers Found It First
CVE-2026-20262 lets an authenticated attacker overwrite arbitrary files on Cisco Catalyst SD-WAN Manager, with a clear path to root. No workaround exists. Exploitation is already underway.

Twenty-Five Orgs Are Quietly Triaging Open-Source Vulns Before You Hear About Them
A coalition called Athena is building shared infrastructure to find, fix, and harden OSS projects in the window between discovery and public disclosure.

CISA Adds LiteSpeed cPanel Plugin Bug to KEV After In-the-Wild Exploitation
CVE-2026-54420 (CVSS 8.5) lets attackers escalate to root on hosts running the LiteSpeed cPanel plugin. Federal agencies have until June 18, 2026 to patch.

Cisco Patches Catalyst SD-WAN Manager Bug Already Seeing In-the-Wild Abuse
CVE-2026-20262 lets an authenticated remote user write files on the appliance. Cisco confirms exploitation. Severity is rated medium, but the access it enables is not.

Weekly Recap: Chrome Zero-Day, UniFi RCE, macOS Stealers, and a VPN Auth Bypass
Another seven days of rented phishing kits, AI-themed lures, and forgotten software paying out as initial access.

Palo Alto Confirms In-the-Wild Abuse of GlobalProtect Auth Bypass (CVE-2026-0257)
An unknown actor is exploiting a 7.8-rated authentication bypass in PAN-OS portals and gateways to slip past GlobalProtect logins.

Splunk Patches CVE-2026-20253, a 9.8-Rated Unauthenticated RCE in Enterprise
The advisory covers Splunk Enterprise builds below 10.2.4 and 10.0.7, with fixed versions now available.

GreatXML's BitLocker Bypass Claim Falls Short — For Now
A pseudonymous researcher dropped an alleged WinRE-based BitLocker exploit days after Patch Tuesday. A respected vulnerability analyst couldn't replicate it. The researcher is already hunting a fix.

ShinyHunters Rode a PeopleSoft Zero-Day Into University Networks
A CVSS 9.8 RCE flaw in Oracle PeopleSoft gave UNC6240 a two-week head start before Oracle even confirmed the bug existed.

CISA Gives Agencies 72 Hours on Ivanti Sentry Bug Under New Emergency Directive
BOD 26-04 sets a sharper clock for actively exploited flaws. First target: an Ivanti Sentry vulnerability already in attackers' hands.

Langflow Path Traversal Flaw CVE-2026-5027 Hits CISA's Exploited List
An unauthenticated write-anywhere bug in the open-source AI builder is being abused in the wild, per VulnCheck telemetry, raising fresh questions for federal users bound by BOD 22-01 patch deadlines.

GreatXML Bypasses BitLocker Through a Trusted Recovery Path
A researcher's four-hour weekend project shows how Windows' own offline scan plumbing can sidestep full-disk encryption.