Daily Threat Briefing
Briefings
SP Page Builder extension for Joomla · SP LMS · iCagenda extension for Joomla
Today's most significant new developments are two critical unauthenticated remote code execution vulnerabilities in widely deployed Joomla extensions (SP Page Builder and SP LMS), a North Korean…
Paperclip AI · Gogs · Windows hosts with low-privilege user sessions
Today's most significant new developments are a Metasploit module for an unauthenticated RCE chain in Paperclip AI (CVE-2026-41679), active exploitation of a Gravity SMTP WordPress plugin information…
Splunk Enterprise · NGINX Open Source and NGINX Plus · pgAdmin 4
The most significant new developments today are the CISA KEV addition of CVE-2026-20253 (Splunk Enterprise missing authentication, due 2026-06-21), a CISA alert and UK NCSC advisory on the FortiBleed…
Microsoft Defender · PTC Windchill PDMLink · libssh2
Today's most significant new developments are a Dropping Elephant espionage campaign using a China-themed lure and a heavily reworked memory-resident RAT with full IOCs published, a "FortiBleed"…
Joomla Content Editor · Microsoft Defender · Google Android 17
CISA has added CVE-2026-48907, a maximum-severity improper access control flaw in the Joomla Content Editor (JCE) plugin, to the KEV catalog with a remediation deadline of 2026-06-19. A coordinated…
Cisco Catalyst SD-WAN Manager · PAN-OS GlobalProtect portal and gateway components · elixir-grpc grpc
Three high-priority items dominate today's briefing: Cisco Catalyst SD-WAN Manager CVE-2026-20262 has been added to the CISA KEV with a confirmed zero-day exploitation history and a June 29…
LiteSpeed cPanel plugin · GL.iNet GL-MT3000 · Ruijie EG105G-P firmware
The Oracle PeopleSoft CVE-2026-35273 CISA KEV remediation deadline expires today; any unfederal agency or organization treating this as a benchmark must patch immediately. New items today include a…
Splunk Enterprise · BUK TS-G Gas Station Automation System · MCP Toolbox for Databases
Today's most significant new item is a critical unauthenticated remote code execution vulnerability in Splunk Enterprise (CVE-2026-20253, CVSS 9.8), which allows arbitrary file operations and code…
vm2 · ChromaDB Python project · Aqara Cloud Production API
Today's most operationally significant new items are: a CVSS 10.0 sandbox escape in vm2 (Node.js) enabling host-process code execution, a critical authentication bypass in SimpleHelp's OIDC flow…
Oracle PeopleSoft · Ivanti Sentry · 389-ds-base
The dominant new development today is the confirmed exploitation of a zero-day in Oracle PeopleSoft (CVE-2026-35273) by the ShinyHunters group (tracked as UNC6240 by Mandiant), with universities and…
Ivanti Sentry · Splunk Enterprise · Langflow
The most significant new developments on 2026-06-11 are two critical Ivanti Sentry vulnerabilities enabling unauthenticated remote code execution, confirmed by both CERT-EU and BSI as requiring…
Google Chrome · Veeam Backup and Replication · Adobe Campaign Classic
June 10 brings a large-scale Microsoft Patch Tuesday release alongside critical new vulnerabilities in Adobe ColdFusion, Adobe Campaign Classic, and Veeam Backup and Replication. Three new CISA KEV…
Check Point Security Gateway · SAP NetWeaver Application Server ABAP and ABAP Platform · SAP NetWeaver Application Server Java
The most critical new developments today are the CISA KEV addition of two actively exploited vulnerabilities: CVE-2026-50751 in Check Point Security Gateway (IKEv1 authentication bypass, CISA…
Comodo Internet Security · WordPress Seotheme · WordPress Background Image Cropper plugin
Today's most significant new development is the public disclosure of CVE-2026-49494, a remotely exploitable kernel-level denial-of-service vulnerability in Comodo Internet Security's firewall driver,…
Cisco Catalyst SD-WAN Manager · GL.iNet GL-MT3000 router · Booking Package plugin for WordPress
The most significant new development in the past 24 hours is the expansion of the Miasma supply chain worm to 73 Microsoft GitHub repositories across four major Microsoft organizations, including…
Mirasvit Full Page Cache Warmer · SolarWinds Serv-U · Everest Forms Pro WordPress plugin
The past 72 hours have seen a high volume of critical and actively exploited vulnerabilities across enterprise and web platforms. CISA added two entries to its Known Exploited Vulnerabilities…
Mirasvit Full Page Cache Warmer · Android Framework · Linux Kernel
The current threat landscape is dominated by several high-priority items requiring immediate attention. CISA has added three vulnerabilities to its Known Exploited Vulnerabilities catalog within the…
Mirasvit Full Page Cache Warmer · Oracle WebLogic Server · Android Framework
The past 72 hours have seen a high volume of actionable threat activity. CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog, including an actively exploited Android…
Oracle WebLogic Server · Android Framework · Linux Kernel
Three actively exploited vulnerabilities dominate today's briefing: Oracle WebLogic Server (CVE-2024-21182), Android Framework (CVE-2025-48595), and Linux Kernel (CVE-2022-0492) have all been added…
Oracle WebLogic Server · Palo Alto Networks PAN-OS · Apache Solr
The past 72 hours have seen a high volume of critical and high-severity vulnerability disclosures alongside several active exploitation events. Key priorities for defenders today include an actively…
Palo Alto Networks PAN-OS · Oracle WebLogic Server · Apache Solr
Today's briefing is dominated by several high-priority items requiring immediate attention. The Palo Alto Networks PAN-OS authentication bypass (CVE-2026-0257) is under active exploitation and has a…