← All briefings

Google Chrome · Veeam Backup and Replication · Adobe Campaign Classic

DAILY THREAT INTELLIGENCE BRIEFING Date: 2026-06-10 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership

EXECUTIVE SUMMARY

June 10 brings a large-scale Microsoft Patch Tuesday release alongside critical new vulnerabilities in Adobe ColdFusion, Adobe Campaign Classic, and Veeam Backup and Replication. Three new CISA KEV additions require immediate attention: an actively exploited Chrome V8 out-of-bounds read/write (CVE-2026-11645), an Arista EOS tunnel decapsulation flaw (CVE-2026-7473), and a Cisco Catalyst SD-WAN Manager privilege escalation (CVE-2026-20245). The BSI has published new advisories for TYPO3, strongSwan, SAP, Wazuh Manager, and Apache HTTP Server. The Miasma supply chain campaign has spawned a new wave called Hades, poisoning 19 PyPI packages with a credential stealer. A critical Veeam RCE (CVE-2026-44963, CVSS 9.4) allows any authenticated domain user to execute code on the backup server, a high-value target in ransomware pre-staging.

CRITICAL VULNERABILITIES

CVE-2026-11645 (NEW - ACTIVELY EXPLOITED)

  • Affected products: Google Chrome prior to 149.0.7827.103; Microsoft Edge, Opera, and all Chromium-based browsers
  • Severity: High (CVSS 8.8; CWE-787 Out-of-Bounds Write, CWE-125 Out-of-Bounds Read)
  • Exploitation status: Actively exploited in the wild; added to CISA KEV 2026-06-09; CISA deadline 2026-06-23
  • Technical detail: An out-of-bounds read and write in the V8 JavaScript and WebAssembly engine allows a remote attacker to execute arbitrary code inside the browser sandbox via a crafted HTML page. Sandbox escape potential makes this a critical endpoint risk.
  • Remediation: Update Chrome to 149.0.7827.103 or later immediately. Apply equivalent updates for Edge and Opera. BSI advisory WID-SEC-2026-1819 covers this. Prioritize managed endpoints and kiosk/shared systems.

CVE-2026-44963 (NEW)

  • Affected products: Veeam Backup and Replication (all versions prior to the June 2026 patch)
  • Severity: Critical (CVSS 9.4)
  • Exploitation status: No confirmed in-the-wild exploitation at time of writing; patch released 2026-06-09
  • Technical detail: Any authenticated domain user can trigger remote code execution on the Veeam Backup Server. Veeam infrastructure is a primary target in ransomware pre-staging operations; attackers who compromise a domain account can leverage this to destroy or encrypt backups before deploying ransomware.
  • Remediation: Apply the Veeam June 2026 security patch immediately. Restrict Veeam server access to dedicated backup administrator accounts. Isolate Veeam infrastructure from general domain user access at the network level. BSI advisory WID-SEC-2026-1834 covers this.

CVE-2026-48303 (NEW)

  • Affected products: Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier
  • Severity: Critical (CVSS 10.0; CWE-863 Incorrect Authorization)
  • Exploitation status: No confirmed exploitation; published 2026-06-09 (APSB26-66)
  • Technical detail: An incorrect authorization vulnerability allows an unauthenticated remote attacker to execute arbitrary code in the context of the current user with no user interaction required and with scope change. A CVSS 10.0 score with no authentication requirement makes this the highest-priority Adobe item this cycle.
  • Remediation: Apply Adobe security update APSB26-66 immediately. Adobe Campaign Classic is widely deployed in European marketing and CRM environments.

CVE-2026-47928 / CVE-2026-47929 / CVE-2026-47930 / CVE-2026-47931 / CVE-2026-47932 (NEW - CONSOLIDATED)

  • Affected products: Adobe ColdFusion 2023.19, 2025.8 and earlier
  • Severity: Critical to High (CVSS 9.6 to 8.1; multiple CWEs including CWE-20, CWE-863, CWE-22)
  • Exploitation status: No confirmed exploitation; published 2026-06-09 (APSB26-64)
  • Technical detail: Five vulnerabilities patched in a single advisory. CVE-2026-47928 (CVSS 9.6) is an improper input validation flaw allowing unauthenticated adjacent-network RCE with scope change. CVE-2026-47929 (CVSS 8.4) is an incorrect authorization flaw exploitable by a high-privileged attacker for RCE. CVE-2026-47930 (CVSS 8.1) allows a low-privileged attacker to bypass security controls and gain unauthorized read/write access. CVE-2026-47931 and CVE-2026-47932 add further RCE and path traversal vectors.
  • Remediation: Apply Adobe APSB26-64 immediately. ColdFusion servers exposed to adjacent networks or the internet should be treated as highest priority.

CVE-2026-45657 (NEW)

  • Affected products: Windows Kernel (all supported Windows versions)
  • Severity: Critical (CVSS 9.8; CWE-416 Use-After-Free)
  • Exploitation status: No confirmed exploitation; published as part of June 2026 Patch Tuesday
  • Technical detail: A use-after-free in the Windows Kernel allows an unauthenticated remote attacker to execute arbitrary code over a network. Network-exploitable kernel vulnerabilities without authentication requirements are rare and warrant accelerated patching.
  • Remediation: Apply June 2026 Patch Tuesday updates. Prioritize internet-facing Windows systems and domain controllers.

CVE-2026-47291 (NEW)

  • Affected products: Windows HTTP.sys (all supported Windows versions)
  • Severity: Critical (CVSS 9.8; CWE-190 Integer Overflow)
  • Exploitation status: No confirmed exploitation; published June 2026 Patch Tuesday
  • Technical detail: An integer overflow in Windows HTTP.sys allows an unauthenticated remote attacker to execute code over a network. HTTP.sys is the kernel-mode HTTP listener used by IIS and many Windows services, making this broadly exploitable against Windows web servers.
  • Remediation: Apply June 2026 Patch Tuesday updates. Prioritize IIS servers and any Windows systems with HTTP.sys exposed to untrusted networks.

CVE-2026-44815 (NEW)

  • Affected products: Windows DHCP Client (all supported Windows versions)
  • Severity: Critical (CVSS 9.8; CWE-121 Stack-Based Buffer Overflow)
  • Exploitation status: No confirmed exploitation; published June 2026 Patch Tuesday
  • Technical detail: A stack-based buffer overflow in the Windows DHCP Client allows an unauthenticated remote attacker to execute code over a network. Any Windows endpoint receiving DHCP responses from a malicious or compromised DHCP server is potentially at risk.
  • Remediation: Apply June 2026 Patch Tuesday updates. Assess exposure in environments with untrusted network segments or guest Wi-Fi.

CVE-2026-42904 (NEW)

  • Affected products: Windows TCP/IP stack (all supported Windows versions)
  • Severity: Critical (CVSS 9.6; CWE-122 Heap-Based Buffer Overflow)
  • Exploitation status: No confirmed exploitation; published June 2026 Patch Tuesday
  • Technical detail: A heap-based buffer overflow in the Windows TCP/IP stack allows an unauthenticated adjacent-network attacker to elevate privileges with scope change. Exploitable from the local network segment without credentials.
  • Remediation: Apply June 2026 Patch Tuesday updates. Segment internal networks to limit adjacent-network exposure.

CVE-2026-45504 (NEW)

  • Affected products: Microsoft Exchange Server
  • Severity: High (CVSS 8.8; CWE-918 Server-Side Request Forgery)
  • Exploitation status: No confirmed exploitation; published June 2026 Patch Tuesday
  • Technical detail: An authenticated attacker with low privileges can exploit an SSRF vulnerability in Exchange Server to elevate privileges over the network. Exchange SSRF vulnerabilities have historically been chained with other flaws for full server compromise.
  • Remediation: Apply June 2026 Patch Tuesday Exchange updates. Review Exchange server exposure and audit authenticated user privilege levels.

CVE-2026-45648 (NEW)

  • Affected products: Active Directory Domain Services (Windows Server)
  • Severity: High (CVSS 8.8; CWE-121 Stack-Based Buffer Overflow)
  • Exploitation status: No confirmed exploitation; published June 2026 Patch Tuesday
  • Technical detail: A stack-based buffer overflow in Active Directory Domain Services allows an authenticated low-privileged attacker to execute code over the network. Domain controllers are the highest-value targets in enterprise environments.
  • Remediation: Apply June 2026 Patch Tuesday updates to all domain controllers immediately.

CVE-2026-46746 / CVE-2026-46748 (NEW - CONSOLIDATED)

  • Affected products: Siemens SINEC INS (all versions prior to V1.0 SP2 Update 6)
  • Severity: High (CVSS 8.8 / 8.7; CWE-78 OS Command Injection, CWE-250 Excessive Privilege)
  • Exploitation status: No confirmed exploitation; published 2026-06-09 via Siemens ProductCERT (SSA-860189)
  • Technical detail: CVE-2026-46746 allows an authenticated remote attacker to inject OS commands via crafted directory names in the SFTP upload endpoint, executed when directory listings are retrieved. CVE-2026-46748 involves a binary with cap_dac_override capability allowing local privilege escalation to root. Both affect SINEC INS, Siemens’ network management system used in industrial and critical infrastructure environments.
  • Remediation: Update SINEC INS to V1.0 SP2 Update 6. Restrict access to the SFTP upload endpoint. Review capability assignments on SINEC INS binaries.

ONGOING

  • CVE-2026-50751 (Check Point Security Gateway): Actively exploited IKEv1 auth bypass; CISA deadline 2026-06-11, apply hotfix sk185033 immediately.
  • CVE-2026-27671 (SAP NetWeaver ABAP): Critical unauthenticated RCE; apply SAP Note 3717897.
  • CVE-2026-44748 (SAP NetWeaver ABAP): Critical XML signature bypass; apply SAP Note 3746332.
  • CVE-2026-40128 (SAP NetWeaver Java): Critical path traversal; apply SAP Note 3727078.
  • CVE-2026-42271 (BerriAI LiteLLM): Actively exploited command injection; CISA deadline 2026-06-22, upgrade to v1.83.7-stable.
  • CVE-2026-23111 (Linux Kernel nf_tables): Public working exploit available; patch all Linux systems, prioritize container hosts.
  • CVE-2026-20245 (Cisco Catalyst SD-WAN Manager): Actively exploited; restrict management plane access, apply vendor patch.
  • CVE-2026-7473 (Arista EOS): Added to CISA KEV 2026-06-09; apply vendor mitigations per Arista advisory 0137.

EUROPEAN ADVISORIES

BSI CERT-Bund - New Advisories (2026-06-09)

WID-SEC-2026-1835 (NEW): The BSI has published a new high-severity advisory for TYPO3 Core. An authenticated remote attacker can exploit multiple vulnerabilities to bypass security restrictions, redirect users to malicious websites, execute arbitrary code, escalate privileges, or cause other impacts. Organizations running TYPO3 CMS, which is widely deployed in German public sector and enterprise web environments, should apply available TYPO3 security updates immediately.

WID-SEC-2026-1834 (NEW): New high-severity advisory for Veeam Backup and Replication covering CVE-2026-44963. See the Critical Vulnerabilities section for full details. Apply the Veeam June 2026 patch immediately.

WID-SEC-2026-1832 (NEW): New high-severity advisory for strongSwan. An unauthenticated remote attacker can exploit a vulnerability to execute arbitrary code. strongSwan is the dominant IPsec VPN implementation on Linux and is widely deployed in German enterprise and government environments. Apply the strongSwan security update immediately. Note that a separate existing advisory (WID-SEC-2025-2846) covering a local security bypass in the NetworkManager plugin was also updated.

WID-SEC-2026-1831 (NEW): SAP June 2026 Patch Day advisory covering multiple vulnerabilities across SAP software products. Impacts include privilege escalation, arbitrary code execution, security bypass, XSS, SQL injection, data manipulation, information disclosure, and denial of service. Organizations running SAP should apply all June 2026 SAP Security Notes. Key items CVE-2026-27671, CVE-2026-44748, and CVE-2026-40128 were covered in yesterday’s report.

WID-SEC-2026-1829 (NEW): Critical advisory for Wazuh Manager. An unauthenticated remote attacker can exploit a vulnerability to escalate privileges. Wazuh is an open-source SIEM and XDR platform widely used in European SOC environments. Organizations running Wazuh Manager should apply the available patch immediately and review for unauthorized access.

WID-SEC-2026-1828 (NEW): New high-severity advisory for VMware Tanzu Spring Framework covering multiple vulnerabilities including privilege escalation, arbitrary code execution, information disclosure, security bypass, data manipulation, XSS, open redirect, and denial of service. Organizations using Spring Framework in Java application development should update to patched versions.

WID-SEC-2026-1824 (NEW): New high-severity advisory for Apache HTTP Server covering multiple vulnerabilities enabling arbitrary code execution, security bypass, XSS, data manipulation, information disclosure, and denial of service. Apply the latest Apache HTTP Server release. Note that two earlier Apache HTTP Server advisories (WID-SEC-2026-1354, WID-SEC-2025-2750) were also updated.

WID-SEC-2026-1818 (NEW): New high-severity advisory for Check Point Remote Access VPN and Mobile Access. Multiple vulnerabilities allow an unauthenticated remote attacker to bypass security controls. This is distinct from CVE-2026-50751 reported yesterday and should be reviewed separately. Apply Check Point patches per vendor guidance.

WID-SEC-2026-1817 (NEW): New high-severity advisory for Checkmk, the widely used open-source IT monitoring platform. Multiple stored XSS vulnerabilities allow an authenticated remote attacker to inject malicious scripts. Organizations using Checkmk should apply available updates.

BSI CERT-Bund - Updated Advisories (2026-06-09)

Gogs (WID-SEC-2026-1739, critical): Updated advisory for a critical RCE vulnerability in the Gogs self-hosted Git service; apply patches immediately if not already done.

Multiple existing advisories updated including Red Hat Enterprise Linux (libsoup), Red Hat Ansible Automation Platform, Mozilla Firefox and Firefox ESR, Golang Go, Linux Kernel (multiple advisories), OpenSSL, LiteLLM, IBM App Connect Enterprise, Apache Tomcat, AMD Processor, GnuTLS, Xen/XenServer, Samba, NGINX, and others. Consult the BSI WID portal for current remediation status on each.

CERT-EU: No new advisories published in the last 24 hours.

ACTIVE THREATS AND CAMPAIGNS

Hades PyPI Supply Chain Campaign (NEW) A new attack wave designated Hades has emerged from the broader Miasma supply chain campaign. Threat actors have poisoned 37 malicious wheel artifacts across 19 packages in the Python Package Index (PyPI). The compromised releases ship a setup.pth file that executes automatically on Python environment initialization, deploying a Bun-based credential stealer