Mirasvit Full Page Cache Warmer · SolarWinds Serv-U · Everest Forms Pro WordPress plugin
DAILY THREAT INTELLIGENCE BRIEFING Date: 2026-06-06 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership
EXECUTIVE SUMMARY
The past 72 hours have seen a high volume of critical and actively exploited vulnerabilities across enterprise and web platforms. CISA added two entries to its Known Exploited Vulnerabilities catalog, including an actively exploited Magento deserialization flaw with a remediation deadline of today (2026-06-06) and a SolarWinds Serv-U denial-of-service vulnerability. Multiple X.Org X server flaws were disclosed, posing privilege escalation risk on Linux systems. The BSI published advisories covering Cisco Unified Communications Manager, Google Chrome, Microsoft Edge, and HTTP/2 implementations. On the threat actor front, China-linked TA4922 has expanded phishing operations to Germany and other European countries. Supply chain attacks targeting the npm ecosystem are ongoing, and FIFA World Cup 2026-themed fraud campaigns are ramping up ahead of the June 11 kickoff. Defenders should prioritize patching KEV entries, reviewing WordPress plugin inventories, and monitoring for IIS-targeting activity from threat cluster OP-512.
CRITICAL VULNERABILITIES
CVE-2026-45247
- Affected products: Mirasvit Full Page Cache Warmer (Magento extension)
- Severity: Critical (CVSS 9.8)
- Exploitation status: Actively exploited in the wild; added to CISA KEV on 2026-06-03
- Remediation: Apply vendor patch immediately. CISA remediation deadline was 2026-06-06. Update to the patched version per Mirasvit changelog. Unauthenticated RCE via crafted serialized PHP object in the CacheWarmer cookie.
CVE-2026-28318
- Affected products: SolarWinds Serv-U (all versions prior to 15.5.4 Hotfix 1)
- Severity: High (CWE-400, uncontrolled resource consumption)
- Exploitation status: Actively exploited; added to CISA KEV on 2026-06-05
- Remediation: Apply SolarWinds Serv-U 15.5.4 Hotfix 1 immediately. CISA deadline: 2026-06-19. Unauthenticated attackers can crash the service via crafted POST requests using Content-Encoding: deflate.
CVE-2026-3300
- Affected products: Everest Forms Pro WordPress plugin (versions up to and including 1.9.12)
- Severity: Critical (CVSS 9.8)
- Exploitation status: Actively exploited in the wild
- Remediation: Update to the patched version immediately. Threat actors are using this RCE flaw to achieve full site compromise. Approximately 4,000 active installations are at risk.
CVE-2025-71317 and CVE-2025-71318
- Affected products: Riello NetMan 204 network management card for UPS systems
- Severity: Critical (CVSS 9.8)
- Exploitation status: Proof-of-concept exploit publicly available on Exploit-DB
- Remediation: CVE-2025-71317 involves a hard-coded backdoor credential (username/password: eurek). CVE-2025-71318 allows unauthenticated access to administrative pages and UPS control commands. Isolate affected devices from internet-facing networks immediately. Check vendor for firmware updates.
CVE-2026-6274
- Affected products: DTS Electronics Redline WR3200 router (versions 7.1.3 to before 7.1.8)
- Severity: Critical (CVSS 9.8)
- Exploitation status: Not confirmed; advisory from Turkish USOM (TR-26-0321)
- Remediation: Update to firmware version 7.1.8 or later. Unauthenticated network access to all functions due to improper authentication.
CVE-2026-50256, CVE-2026-50257, CVE-2026-50258, CVE-2026-50259, CVE-2026-50260, CVE-2026-50261, CVE-2026-50264
- Affected products: X.Org X server and Xwayland (multiple versions)
- Severity: High (CVSS 7.8 each)
- Exploitation status: Not confirmed in the wild; patches available
- Remediation: Apply upstream patches from the X.Org project. Vulnerabilities include stack-based buffer overflows and use-after-free conditions. If X server runs as root, these flaws can lead to privilege escalation. Coordinated disclosure via xorg-announce mailing list.
CVE-2026-10580
- Affected products: Hippoo Mobile App for WooCommerce WordPress plugin (versions up to 1.9.4)
- Severity: Critical (CVSS 9.8)
- Exploitation status: Not confirmed; patch available
- Remediation: Update immediately. Unauthenticated attackers can reset any WordPress user’s password, including administrators, via a logic flaw in the REST API permission callback.
CVE-2026-20230
- Affected products: Cisco Unified Communications Manager (Unified CM)
- Severity: High
- Exploitation status: Proof-of-concept exploit publicly available; no confirmed in-the-wild exploitation per Cisco PSIRT
- Remediation: Apply Cisco patch immediately. Server-side request forgery allows unauthenticated network attackers to write files and escalate to root. BSI advisory WID-SEC-2026-1801 also covers this issue.
CVE-2026-11332
- Affected products: ansible-core (ansible-galaxy role install)
- Severity: High (CVSS 7.8)
- Exploitation status: Not confirmed; Red Hat advisory published
- Remediation: Update ansible-core. Malicious role authors can inject arbitrary git configuration flags via the src field in meta/requirements.yml, leading to code execution on the installing machine.
EUROPEAN ADVISORIES
BSI CERT-Bund published a high volume of new and updated advisories on 2026-06-05. Key new advisories include:
- WID-SEC-2026-1801: Cisco Unified Communications Manager - unauthenticated remote file write with potential root escalation (CVE-2026-20230). Exploit code is public.
- WID-SEC-2026-1794: Google Chrome and Microsoft Edge - multiple vulnerabilities including arbitrary code execution and security bypass. Immediate browser updates recommended.
- WID-SEC-2026-1792: Microsoft Cloud Services (Azure HorizonDB, Exchange Online, Microsoft 365 Copilot, Copilot Chat in Edge) - privilege escalation, code execution, and information disclosure.
- WID-SEC-2026-1791: HTTP/2 implementations - remote denial-of-service affecting NGINX, Apache HTTPD, Microsoft IIS, Envoy, and Cloudflare Pingora. Affects default HTTP/2 configurations.
- WID-SEC-2026-1806: Budibase - multiple vulnerabilities allowing security bypass and file manipulation.
- WID-SEC-2026-1804: BigBlueButton - SQL injection and information spoofing vulnerabilities. Relevant for organizations using this open-source video conferencing platform.
- WID-SEC-2026-1800: MISP - multiple vulnerabilities in the threat intelligence sharing platform. Relevant to SOC and threat intelligence teams using MISP instances.
- WID-SEC-2026-1788 (UNPATCHED): Cisco Catalyst SD-WAN Manager - local privilege escalation. No patch available at time of publication. Apply compensating controls.
- WID-SEC-2026-1802: Linux Kernel - multiple vulnerabilities enabling denial of service. Numerous Linux Kernel advisories were also updated.
Organizations running Cisco UC infrastructure, BigBlueButton for remote collaboration, or MISP for threat intelligence sharing should prioritize review of these advisories.
ACTIVE THREATS AND CAMPAIGNS
TA4922 - China-Linked Phishing Expansion to Europe
- A China-linked threat group designated TA4922 has expanded phishing operations to target organizations in Germany, the United Kingdom, Italy, and South Africa.
- The group uses ValleyRAT (also known as Winos 4.0) and Atlas RAT as primary payloads.
- Operational tempo is described as rapid with a continuously evolving malware arsenal.
- German organizations should treat unsolicited emails with executable attachments or credential-harvesting links with elevated suspicion.
OP-512 - IIS Web Shell Campaign
- A previously unreported threat cluster designated OP-512 has been observed targeting Microsoft Internet Information Services (IIS) servers to deploy a custom web shell framework.
- Attribution assessed with moderate to high confidence as China-linked espionage activity.
- Organizations running internet-facing IIS servers should review web shell detection rules and audit recently modified files in web root directories.
npm Supply Chain Attacks - IronWorm and Miasma Worm
- Two concurrent supply chain attacks are targeting the npm ecosystem.
- IronWorm distributes a Rust-based information stealer that scrapes developer secrets and hides behind an eBPF kernel rootkit.
- A new Miasma worm variant poisons over 50 legitimate npm packages and is self-spreading.
- Development teams and CI/CD pipelines consuming npm packages should audit dependencies and review recent package updates for unexpected behavior.
PCPJack - Cloud SMTP Relay Hijacking
- The threat actor PCPJack has compromised approximately 230 cloud servers across AWS, Google Cloud, and Azure to build a covert SMTP relay network.
- Compromised servers in Europe are included. The infrastructure is used to send spam or phishing at scale while blending into legitimate cloud traffic.
- Cloud administrators should audit outbound SMTP activity and review for unauthorized relay configurations.
FIFA World Cup 2026 Fraud Campaign
- Security researchers and the FBI are warning of active FIFA-themed fraud ahead of the June 11 tournament kickoff.
- Observed activity includes thousands of lookalike FIFA domains, banking malware embedded in pirate streaming applications, and credential-harvesting pages mimicking the official FIFA login portal.
- Organizations should brief employees and block known malicious FIFA-themed domains at the perimeter.
FlutterShell macOS Backdoor
- A macOS malvertising campaign (Operation FlutterBridge) is distributing a new backdoor called FlutterShell via malicious Google and YouTube advertisements.
- Linked to a previously tracked cluster (JSCoreRunner/FileRipple). Targets macOS users who click on malicious ads impersonating legitimate software.
DesckVB RAT via Google DoubleClick Abuse
- A malspam campaign is routing victims through Google’s DoubleClick domain to evade detection before delivering the DesckVB remote access trojan.
- The use of a trusted Google-owned domain reduces the likelihood of detection by email security gateways.
Stock Exchange Executive Email Espionage
- Attackers maintained persistent access to the Outlook mailbox of a senior executive at a major global stock exchange for at least five months.
- Data was exfiltrated in small batches via Dropbox and OneDrive to blend with normal cloud traffic. Assessed as espionage-motivated.
- Financial sector organizations should review anomalous cloud storage egress patterns and implement mailbox audit logging.
SECURITY NEWS AND CONTEXT
- Cisco patched CVE-2026-20230 in Unified Communications Manager. Public proof-of-concept exploit code is available, significantly reducing the time to exploitation. Patching is urgent.
- The HTTP/2 Bomb vulnerability affects default configurations of NGINX, Apache HTTPD, Microsoft IIS, Envoy, and Cloudflare Pingora. The BSI has issued an advisory. Organizations should review HTTP/2 configuration hardening guidance from respective vendors.
- An autonomous AI tool discovered CVE-2026-23479, a two-year-old use-after-free RCE flaw in Redis (introduced in version 7.2.0). Redis has released patches. Organizations running Redis should update immediately.
- A flaw in Anthropic’s Claude Code GitHub Action allowed repository takeover via a single malicious GitHub issue. The issue has been patched. Organizations using AI-integrated CI/CD workflows should audit GitHub Action permissions and restrict write access.
- An unpatched Windows Search URI handler vulnerability can be exploited to steal NTLMv2 hashes. No CVE patch is available yet. Organizations should consider disabling or restricting the search: URI handler as a compensating control.
- A development debug flag left enabled in production builds of several Microsoft 365 Android apps allowed any co-installed app to steal account tokens without user interaction. Microsoft has addressed the issue. Ensure Microsoft 365 Android apps are updated.
RECOMMENDED ACTIONS
-
PATCH IMMEDIATELY: Apply the Mirasvit Full Page Cache Warmer patch today. The CISA KEV remediation deadline is 2026-06-06. Unauthenticated RCE is confirmed in the wild.
-
PATCH URGENTLY: Update SolarWinds Serv-U to version 15.5.4 Hotfix 1. Unauthenticated denial-of-service is actively exploited. CISA deadline is 2026-06-19.
-
CISCO UCM: Apply the patch for CVE-2026-20230 immediately. Public exploit code is available. Prioritize internet-facing or network-accessible Unified CM deployments.
-
WORDPRESS ENVIRONMENTS: Audit all WordPress installations for the following vulnerable plugins: Everest Forms Pro (up to 1.9.12), Hippoo for WooCommerce (up to 1.9.4), WP Captcha PRO (up to 5.38), Admin Columns (up to 7.0.18), WP User Manager (up to 2.9.17), and All-In-One Security (up to 5.4.7). Update or remove affected plugins.
-
IIS SERVERS: Implement web shell detection monitoring on all internet-facing IIS servers. Review recently modified files in web directories. Correlate with OP-512 indicators if available from your threat intelligence feeds.
-
NPM PIPELINES: Audit npm dependencies in development and CI/CD environments. Verify package integrity and review recent updates for unexpected behavior. Consider using lockfiles and dependency pinning.
-
LINUX SYSTEMS: Apply X.Org X server patches and available Linux Kernel updates. Prioritize systems where the X server runs as root.
-
NETWORK DEVICES: Isolate Riello NetMan 204 UPS management cards from internet-facing networks. Change or disable the hard-coded backdoor account (username: eurek) if possible pending vendor firmware guidance.
-
THREAT AWARENESS: Brief staff on FIFA World Cup 2026 phishing and fraud themes. Block lookalike FIFA domains at the perimeter. Warn against pirate streaming applications.
-
CLOUD MONITORING: Review outbound SMTP traffic from cloud-hosted servers for signs of PCPJack relay abuse. Audit cloud storage egress for anomalous patterns consistent with email exfiltration.