← All briefings

Oracle WebLogic Server · Palo Alto Networks PAN-OS · Apache Solr

DAILY THREAT INTELLIGENCE BRIEFING Date: 2026-06-02 Prepared for: SOC Analysts, Incident Responders, Vulnerability Management, Security Leadership

EXECUTIVE SUMMARY

The past 72 hours have seen a high volume of critical and high-severity vulnerability disclosures alongside several active exploitation events. Key priorities for defenders today include an actively exploited Oracle WebLogic Server vulnerability added to the CISA KEV catalog, a PAN-OS GlobalProtect authentication bypass under active exploitation, and a critical WordPress plugin flaw being weaponized to create rogue admin accounts. IBM WebSphere Application Server has received multiple critical patches covering remote code execution and identity spoofing. Apache Solr has a hardcoded credentials issue enabling full administrative access. On the threat campaign front, a supply chain attack dubbed Miasma has compromised Red Hat npm packages, and a China-aligned espionage campaign (Operation Dragon Weave) is actively targeting European entities including the Czech Republic. Dutch authorities have dismantled a large botnet linked to 17 million infected devices.

CRITICAL VULNERABILITIES

CVE-2024-21182

  • Affected products: Oracle WebLogic Server
  • Severity: Critical (CVSS 9.8)
  • Exploitation status: Actively exploited - added to CISA KEV on 2026-06-01, remediation due 2026-06-04
  • Description: Unauthenticated attacker with network access via T3 or IIOP can compromise the server and gain full access to all accessible data
  • Remediation: Apply Oracle CPU July 2024 patches immediately. If patching is not possible, restrict T3 and IIOP access at the network perimeter. Treat as emergency priority given CISA KEV inclusion and tight due date

CVE-2026-0257

  • Affected products: Palo Alto Networks PAN-OS, Prisma Access (GlobalProtect)
  • Severity: High (CVSS 7.8)
  • Exploitation status: Actively exploited in the wild as of 2026-05-30
  • Description: Authentication bypass in GlobalProtect allowing unauthenticated attackers to establish unauthorized VPN connections
  • Remediation: Apply Palo Alto Networks patches immediately. Review VPN connection logs for anomalous authentication events. BSI has issued an updated advisory for PAN-OS

CVE-2026-44825

  • Affected products: Apache Solr 9.4.0 through 9.10.1, 10.0.0
  • Severity: Critical (CVSS 9.8 per NVD)
  • Exploitation status: Not confirmed exploited in the wild; publicly disclosed
  • Description: Hardcoded default credentials (superadmin, admin, search, index) silently installed by the BasicAuth setup tool allow unauthenticated full administrative access
  • Remediation: Delete or change passwords for template users in security.json immediately. Upgrade to Solr 9.11.0 or 10.1.0 when available. BSI issued a new advisory on 2026-06-01

CVE-2026-9311 and CVE-2026-9319

  • Affected products: IBM WebSphere Application Server 8.5, 9.0
  • Severity: Critical (CVSS 9.0)
  • Exploitation status: No confirmed exploitation; vendor-disclosed
  • Description: CVE-2026-9311 allows remote code execution via security control bypass. CVE-2026-9319 allows RCE via deserialization of untrusted data through JAX-WS endpoints with WS-Security
  • Remediation: Apply IBM security patches per advisory nodes 7274733 and 7274738. BSI has issued an advisory covering IBM WebSphere Application Server

CVE-2026-8644

  • Affected products: IBM WebSphere Application Server 8.5, 9.0
  • Severity: Critical (CVSS 9.1)
  • Exploitation status: No confirmed exploitation; vendor-disclosed
  • Description: Identity spoofing vulnerability allowing unauthenticated remote attackers to manipulate integrity and availability
  • Remediation: Apply IBM patch per advisory node 7274740

CVE-2026-8206

  • Affected products: Kirki Freeform Page Builder / Website Builder WordPress plugin, versions 6.0.0 to 6.0.6
  • Severity: Critical (CVSS 9.8)
  • Exploitation status: No confirmed exploitation; publicly disclosed
  • Description: Unauthenticated privilege escalation via account takeover - password reset link for any registered user can be redirected to attacker-controlled email
  • Remediation: Update Kirki plugin to version 6.0.7 or later immediately. Audit WordPress admin accounts for unauthorized additions

WP Maps Pro (no CVE assigned in available data)

  • Affected products: WP Maps Pro WordPress plugin (over 15,000 sales)
  • Severity: Critical
  • Exploitation status: Actively exploited - threat actors creating rogue administrator accounts
  • Remediation: Update to the latest patched version immediately. Audit WordPress admin user lists for unauthorized accounts. Consider temporarily disabling the plugin if patching is not immediately possible

CVE-2026-9330

  • Affected products: IBM WebSphere Application Server 8.5, 9.0
  • Severity: High (CVSS 8.5)
  • Exploitation status: No confirmed exploitation; vendor-disclosed
  • Description: RCE via deserialization of untrusted data in the SAML Web Single Sign-On component when combined with a suitable gadget chain
  • Remediation: Apply IBM patch per advisory node 7274733

CVE-2026-47294

  • Affected products: Microsoft Office SharePoint
  • Severity: High (CVSS 8.0)
  • Exploitation status: No confirmed exploitation; vendor-disclosed
  • Description: Deserialization of untrusted data allows an authorized attacker to execute code over a network
  • Remediation: Apply Microsoft security updates via MSRC update guide

EUROPEAN ADVISORIES

BSI CERT-Bund issued a high volume of advisories on 2026-06-01 and 2026-06-02. The following are the most operationally relevant for enterprise environments:

  • Apache ActiveMQ (updated, HIGH): Multiple vulnerabilities enabling XSS, information disclosure, privilege escalation, data manipulation, and code execution. Operators running ActiveMQ should apply the latest patches without delay.

  • Apache Solr (new, HIGH): Hardcoded credentials vulnerability (CVE-2026-44825) enabling unauthenticated administrative access. See Critical Vulnerabilities section above.

  • IBM WebSphere Application Server (updated, HIGH): Multiple RCE and identity spoofing vulnerabilities. See Critical Vulnerabilities section above.

  • IBM Business Automation Workflow (new, HIGH): Multiple vulnerabilities including security bypass, DoS, information disclosure, file manipulation, and XSS. Organizations using IBM BAW should review and apply available patches.

  • JetBrains IntelliJ IDEA (new, HIGH): Multiple vulnerabilities enabling arbitrary code execution and information disclosure. Developer workstations running IntelliJ IDEA should be updated.

  • OTRS (new, HIGH): Multiple vulnerabilities including DoS, SQL injection, information disclosure, and XSS. Relevant for organizations using OTRS as a ticketing or service management platform.

  • Palo Alto Networks PAN-OS (updated, HIGH): Multiple vulnerabilities including active exploitation of CVE-2026-0257. See Critical Vulnerabilities section.

  • Laravel (new, HIGH): Vulnerability enabling data manipulation by unauthenticated remote attackers. PHP application teams using Laravel should review the advisory.

  • Golang Go (updated, HIGH): Multiple vulnerabilities including memory corruption, code execution, security bypass, and DoS. Relevant for all teams building or running Go-based services.

  • Linux Kernel (multiple advisories, HIGH): Numerous updated advisories covering privilege escalation, DoS, memory corruption, and code execution. Linux system administrators should review pending kernel updates.

  • Mozilla Firefox and Thunderbird (updated, HIGH): Multiple vulnerabilities including code execution, sandbox escape, and privilege escalation. Ensure browsers are updated to the latest stable release.

  • Samba (updated, HIGH): Multiple vulnerabilities enabling code execution, DoS, file manipulation, and security bypass. Relevant for environments using Samba for file sharing or Active Directory integration.

  • MariaDB (new, HIGH): Multiple unspecified vulnerabilities. Database administrators should review and apply available MariaDB updates.

ACTIVE THREATS AND CAMPAIGNS

Miasma Supply Chain Attack - Red Hat npm Packages

  • A supply chain campaign designated Miasma has compromised packages under the @redhat-cloud-services npm namespace
  • The malicious packages execute at install time, harvest credentials and secrets from developer machines, target CI/CD pipeline configurations, and deploy a self-propagating worm with encrypted exfiltration capabilities
  • Tactics mirror the previously observed Mini Shai-Hulud campaign
  • Recommended actions: Audit npm dependencies for @redhat-cloud-services packages, review CI/CD pipeline integrity, rotate any credentials that may have been exposed on affected developer machines, check for unexpected outbound connections from build systems

OpenAI Codex Supply Chain Attack - codexui-android npm Package

  • A malicious npm package named codexui-android is masquerading as a remote web UI for OpenAI Codex and has accumulated over 29,000 weekly downloads
  • The package steals OpenAI Codex authentication tokens
  • The package remains available on npm at time of reporting
  • Recommended actions: Remove codexui-android from any development environments, rotate any OpenAI API keys or Codex authentication tokens on affected systems, audit npm package inventories

Operation Dragon Weave - China-Aligned Espionage Campaign

  • A cyber espionage campaign designated Operation Dragon Weave has been observed targeting government, research, academic, technology, and financial services sectors in the Czech Republic and Taiwan
  • The campaign delivers an AdaptixC2 agent via spear-phishing emails containing ZIP attachments
  • Attribution is to a China-aligned threat group (confidence: moderate, based on Seqrite Labs reporting)
  • European organizations, particularly those with government or research affiliations, should treat this as a relevant threat given the Czech Republic targeting
  • Recommended actions: Review email gateway rules for ZIP attachment filtering, brief staff on spear-phishing awareness, monitor for AdaptixC2 indicators in network traffic

Dashlane Brute-Force Attack

  • Dashlane disclosed on 2026-05-31 that an external threat actor conducted a brute-force attack against user accounts targeting 2FA bypass
  • Fewer than 20 personal subscription users had encrypted vaults downloaded
  • No enterprise accounts reported affected at time of disclosure
  • Recommended actions: Organizations using Dashlane for credential management should verify account security settings, enforce strong 2FA, and monitor for any credential exposure notifications from Dashlane

Dutch Botnet Takedown

  • Dutch authorities (Politie and NCSC) dismantled a botnet comprising at least 17 million infected devices, with over 200 command-and-control servers located in the Netherlands
  • The takedown is a significant European law enforcement success
  • Organizations should check endpoint security telemetry for any devices that may have been part of this infrastructure

SECURITY NEWS AND CONTEXT

  • PAN-OS CVE-2026-0257 is confirmed under active exploitation. Palo Alto Networks has issued warnings and BSI has updated its advisory. This should be treated as an emergency patch priority for all organizations running GlobalProtect VPN.

  • The Miasma and codexui-android campaigns represent a continued and escalating trend of supply chain attacks targeting developer toolchains and CI/CD pipelines. The use of self-propagating worm components in Miasma marks an increase in sophistication compared to earlier credential-harvesting campaigns.

  • The weekly recap from The Hacker News highlights a broader pattern of AI-assisted attacks, OAuth phishing campaigns, and exploitation of recently patched vulnerabilities. Defenders should assume that any publicly disclosed vulnerability with a proof-of-concept will be weaponized within days.

  • IBM WebSphere Application Server has received four separate critical and high-severity CVEs in this reporting period, making it a high-priority patching target for enterprise Java application environments.

RECOMMENDED ACTIONS

  1. EMERGENCY - Patch Oracle WebLogic Server immediately for CVE-2024-21182. CISA remediation deadline is 2026-06-04. Restrict T3 and IIOP access at the network level as an interim control.

  2. EMERGENCY - Apply Palo Alto Networks patches for CVE-2026-0257 (PAN-OS GlobalProtect authentication bypass). Review VPN logs for unauthorized connection attempts. Isolate unpatched GlobalProtect instances from the internet if patching cannot be completed immediately.

  3. HIGH PRIORITY - Audit Apache Solr deployments for CVE-2026-44825. Remove or change passwords for default template users (superadmin, admin, search, index) in security.json immediately. Do not wait for the upgrade.

  4. HIGH PRIORITY - Apply all available IBM WebSphere Application Server patches covering CVE-2026-9311, CVE-2026-9319, CVE-2026-8644, and CVE-2026-9330. Prioritize internet-facing instances.

  5. HIGH PRIORITY - Audit WordPress environments for the WP Maps Pro plugin. Update immediately and review admin user accounts for unauthorized additions.

  6. HIGH PRIORITY - Audit npm package inventories for @redhat-cloud-services packages and codexui-android. Rotate any potentially exposed credentials and API tokens. Review CI/CD pipeline integrity.

  7. MEDIUM PRIORITY - Update Kirki WordPress plugin to version 6.0.7 or later to address CVE-2026-8206 account takeover vulnerability.

  8. MEDIUM PRIORITY - Brief security and development teams on Operation Dragon Weave spear-phishing tactics. Reinforce email attachment handling procedures, particularly for ZIP files from external senders.

  9. ONGOING - Apply BSI-flagged patches for Apache ActiveMQ, IBM Business Automation Workflow, JetBrains IntelliJ IDEA, OTRS, Laravel, Golang, Samba, MariaDB, and Linux Kernel as part of the regular patch cycle. Prioritize internet-facing and authentication-critical systems.

  10. ONGOING - Ensure Mozilla Firefox, Thunderbird, and Chromium-based browsers are updated to the latest stable versions across all managed endpoints.