← All briefings

Cisco Catalyst SD-WAN Manager · GL.iNet GL-MT3000 router · Booking Package plugin for WordPress

DAILY THREAT INTELLIGENCE BRIEFING Date: 2026-06-07 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership

EXECUTIVE SUMMARY

The most significant new development in the past 24 hours is the expansion of the Miasma supply chain worm to 73 Microsoft GitHub repositories across four major Microsoft organizations, including Azure and MicrosoftDocs, prompting GitHub to disable access to affected repositories. Separately, Cisco has confirmed active exploitation of CVE-2026-20245 in Catalyst SD-WAN Manager with no patch currently available, requiring immediate compensating controls. A newly disclosed unauthenticated command injection flaw in GL.iNet GL-MT3000 routers (CVE-2026-11450) carries a public proof-of-concept and affects a widely deployed consumer and SMB device. No new CISA KEV entries were published in the last 24 hours, and no new BSI or CERT-EU advisories were issued in this period.

CRITICAL VULNERABILITIES

CVE-2026-20245 (NEW - STATUS CHANGE)

  • Affected products: Cisco Catalyst SD-WAN Manager (On-Prem, SD-WAN Cloud-Pro, SD-WAN Cloud Cisco Managed, SD-WAN for Government FedRAMP)
  • Severity: High (CVSS 7.8)
  • Exploitation status: Actively exploited in the wild per Cisco confirmation
  • Remediation: No patch is currently available. Apply compensating controls immediately: restrict management plane access to trusted IP ranges, disable unnecessary external access to the SD-WAN Manager interface, and monitor for anomalous privilege escalation activity. This was previously noted as unpatched in BSI advisory WID-SEC-2026-1788; active exploitation now confirmed.

CVE-2026-11450 (NEW)

  • Affected products: GL.iNet GL-MT3000 router, firmware version 4.4.5
  • Severity: High (CVSS 7.3 v3.1; unauthenticated remote attack vector)
  • Exploitation status: Public proof-of-concept exploit published on GitHub; no confirmed in-the-wild exploitation reported at time of writing
  • Remediation: Upgrade firmware to version 4.7 or later. The vendor has confirmed that version 4.7 introduces method-level validation at the HTTP /rpc layer, removing nas-web.eject_disk from the allowed method whitelist and blocking the remote exploit chain. The vulnerability is a command injection via the dev_name argument in the dlopen function of the Path Normalization Handler. GL.iNet devices are commonly deployed in SMB, remote work, and travel environments; internet-exposed management interfaces should be restricted immediately pending upgrade.

CVE-2026-9851 (NEW)

  • Affected products: Booking Package plugin for WordPress, versions up to and including 1.7.16
  • Severity: High (CVSS 7.2)
  • Exploitation status: No confirmed exploitation; patch available
  • Remediation: Update to the patched version (changeset 3558752 or later). A missing capability check on the updateUser AJAX endpoint allows authenticated attackers with Editor-level access to change the email address and password of any account, including administrators, resulting in full site takeover. Organizations running WordPress with untrusted editor-level users should treat this as high priority.

CVE-2026-7537 (NEW)

  • Affected products: MDJM Event Management plugin for WordPress, versions up to and including 1.7.8.3
  • Severity: High (CVSS 7.2)
  • Exploitation status: No confirmed exploitation; public PoC available on GitHub
  • Remediation: Update to the latest version. Arbitrary file upload via the mdjm_send_comm_email function with no file type or MIME validation allows administrator-level users to upload executable files and achieve remote code execution. While the attack requires administrator credentials, the public PoC lowers the risk bar for post-compromise escalation scenarios.

CVE-2026-11413 (NEW)

  • Affected products: JingDong JD Cloud Box AX6600, firmware version 4.5.3.r4546
  • Severity: High (CVSS 8.8 v3.1)
  • Exploitation status: Public exploit disclosed; vendor has not responded to disclosure
  • Remediation: No vendor patch available at time of writing. A stack-based buffer overflow in the set_macfilter function of /sbin/jdcweb_rpc is exploitable remotely by authenticated users. Restrict management interface access and isolate devices from untrusted networks. This device is primarily a consumer product but may appear in SMB environments.

ONGOING

  • CVE-2026-28318 (SolarWinds Serv-U): Actively exploited DoS flaw; apply 15.5.4 Hotfix 1, CISA deadline 2026-06-19.
  • CVE-2026-45247 (Mirasvit Full Page Cache Warmer): Actively exploited unauthenticated RCE; CISA deadline passed 2026-06-06, patch immediately if not yet applied.
  • CVE-2026-3300 (Everest Forms Pro WordPress): Actively exploited RCE; update immediately.
  • CVE-2026-20230 (Cisco Unified CM): Public exploit available, unauthenticated root escalation; patch immediately.
  • CVE-2025-71317 / CVE-2025-71318 (Riello NetMan 204): Hard-coded credentials and unauthenticated admin access; isolate from internet-facing networks.
  • CVE-2026-50256 through CVE-2026-50264 (X.Org X server / Xwayland): Privilege escalation flaws; apply upstream patches.
  • CVE-2026-11332 (ansible-core): Code execution via malicious role; update ansible-core.
  • CVE-2026-10580 (Hippoo for WooCommerce): Unauthenticated admin password reset; update immediately.

EUROPEAN ADVISORIES

No new BSI CERT-Bund or CERT-EU advisories were published in the last 24 hours.

Previously reported BSI advisories remain active: WID-SEC-2026-1801 (Cisco UCM), WID-SEC-2026-1794 (Chrome/Edge), WID-SEC-2026-1791 (HTTP/2), WID-SEC-2026-1788 (Cisco SD-WAN Manager - now confirmed exploited), WID-SEC-2026-1800 (MISP), and WID-SEC-2026-1804 (BigBlueButton) remain open. Remediation guidance is unchanged from yesterday’s report.

ACTIVE THREATS AND CAMPAIGNS

Miasma Worm - Microsoft GitHub Repositories Compromised (STATUS CHANGE) The Miasma self-replicating supply chain worm has materially escalated. In the past 24 hours, 73 Microsoft GitHub repositories across four organizations - Azure, Azure-Samples, Microsoft, and MicrosoftDocs - were confirmed compromised. GitHub has disabled access to the affected repositories. This represents a significant expansion from the previously reported npm ecosystem targeting. Development teams and CI/CD pipelines that pull from any of these Microsoft GitHub organizations should treat recent commits with suspicion and verify the integrity of any code consumed from these repositories. Organizations using Azure SDK samples or Microsoft documentation code examples in automated pipelines are at elevated risk. No specific IOCs have been published at time of writing; monitor OpenSourceMalware and GitHub Security advisories for updates.

Cisco SD-WAN Active Exploitation (STATUS CHANGE) CVE-2026-20245 in Cisco Catalyst SD-WAN Manager has moved from unpatched-but-unconfirmed to actively exploited. See the Critical Vulnerabilities section for full details and compensating controls.

ONGOING

  • TA4922 (China-linked): Phishing campaign targeting German and European organizations with ValleyRAT and Atlas RAT payloads; no new developments.
  • OP-512: IIS web shell deployment campaign; continue monitoring web root directories and web shell detection rules.
  • IronWorm (npm): Rust-based infostealer with eBPF rootkit distributed via malicious npm packages; audit dependencies.
  • PCPJack: Cloud SMTP relay hijacking across AWS, GCP, and Azure; audit outbound SMTP from cloud-hosted servers.
  • FIFA World Cup 2026 fraud: Lookalike domains, banking malware in pirate streams, and credential-harvesting pages active ahead of June 11 kickoff.
  • FlutterShell / Operation FlutterBridge: macOS backdoor distributed via malicious Google and YouTube ads; no new developments.
  • DesckVB RAT: Malspam campaign routing through Google DoubleClick to deliver RAT; no new developments.

SECURITY NEWS AND CONTEXT

ChatGPT Lockdown Mode: OpenAI has begun rolling out a new Lockdown Mode for ChatGPT that restricts tools capable of enabling data exfiltration, specifically targeting prompt injection attack vectors. Organizations handling sensitive data that permit employee use of ChatGPT should evaluate enabling this feature and review their AI usage policies.

AI-Discovered FFmpeg Zero-Days and Chrome Record Patch Volume: An autonomous AI agent identified 21 previously unknown vulnerabilities in FFmpeg, the media processing library embedded in a broad range of enterprise and consumer software. Separately, Google shipped Chrome 149 with patches for a record 429 security bugs. Organizations should prioritize Chrome updates and assess FFmpeg exposure in their software inventory as CVE assignments for the AI-discovered flaws are expected to follow.

Smart TV Proxy Abuse via Embedded SDK: A researcher has documented how the Bright Data SDK, embedded in free consumer apps, silently converts devices including always-on smart TVs into residential proxy exit nodes used for web scraping. While not a direct enterprise threat, this technique is relevant to organizations investigating anomalous outbound traffic from IoT or BYOD devices on corporate networks.

RECOMMENDED ACTIONS

  1. CISCO SD-WAN MANAGER: Immediately restrict management plane access for CVE-2026-20245 to trusted IP ranges. No patch is available. Monitor for privilege escalation activity on all affected deployment types.

  2. GL.iNET GL-MT3000: Upgrade firmware to version 4.7 immediately. Restrict management interface access on all internet-exposed devices pending upgrade. A public PoC for CVE-2026-11450 is available.

  3. MIASMA WORM - GITHUB: Audit all CI/CD pipelines and build scripts that reference Microsoft GitHub repositories (Azure, Azure-Samples, Microsoft, MicrosoftDocs organizations). Verify integrity of recently consumed code. Do not pull from disabled repositories until GitHub confirms remediation.

  4. WORDPRESS PLUGINS: Add CVE-2026-9851 (Booking Package up to 1.7.16) and CVE-2026-7537 (MDJM Event Management up to 1.7.8.3) to your WordPress plugin audit. Update both immediately. Review editor-level user accounts for signs of account takeover attempts related to CVE-2026-9851.

  5. CHROME / FFMPEG: Deploy Chrome 149 across all managed endpoints. Inventory software components that embed FFmpeg and monitor for CVE assignments as AI-discovered vulnerabilities are formally catalogued.

  6. CHATGPT ENTERPRISE USE: Evaluate enabling OpenAI’s Lockdown Mode for organizational ChatGPT accounts, particularly where sensitive data may be present in prompts or connected tools.

  7. CISCO UCM: If CVE-2026-20230 patch has not yet been applied, treat as critical priority given public exploit availability.

  8. SOLARWINDS SERV-U: Confirm CVE-2026-28318 patch (15.5.4 Hotfix 1) has been applied. CISA deadline is 2026-06-19.

  9. FIFA FRAUD AWARENESS: Reinforce staff briefing ahead of the June 11 World Cup kickoff. Ensure perimeter controls are blocking known malicious FIFA-themed domains.

  10. Continue remediation of previously reported items: Mirasvit Full Page Cache Warmer (CVE-2026-45247), Everest Forms Pro (CVE-2026-3300), Riello NetMan 204 (CVE-2025-71317/71318), X.Org X server patches, ansible-core update, Hippoo for WooCommerce (CVE-2026-10580), and Linux Kernel updates.