Ivanti Sentry · Splunk Enterprise · Langflow
DAILY THREAT INTELLIGENCE BRIEFING Date: 2026-06-11 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership
EXECUTIVE SUMMARY
The most significant new developments on 2026-06-11 are two critical Ivanti Sentry vulnerabilities enabling unauthenticated remote code execution, confirmed by both CERT-EU and BSI as requiring immediate action. Splunk has disclosed a critical unauthenticated file creation/truncation flaw (CVE-2026-20253, CVSS 9.8) in Enterprise and Cloud Platform via an exposed PostgreSQL sidecar endpoint, alongside a high-severity RCE via unsafe deserialization in Splunk Secure Gateway (CVE-2026-20251). A public proof-of-concept exploit for a Microsoft Defender zero-day named RoguePlanet grants SYSTEM access on fully patched Windows systems. The Windows Netlogon critical RCE is now confirmed actively exploited by threat actors per the Centre for Cybersecurity Belgium. A China-linked reconnaissance botnet (JDY) has expanded to over 1,500 compromised SOHO and IoT devices. An unpatched path traversal in Langflow (CVE-2026-5027) is under active exploitation in the wild.
CRITICAL VULNERABILITIES
CVE-2026-IVANTI-SENTRY (Ivanti Sentry - CERT-EU 2026-008 / BSI WID-SEC-2026-1841)
- Affected products: Ivanti Sentry (all affected versions per vendor advisory)
- Severity: Critical (BSI rated kritisch; unauthenticated RCE)
- Exploitation status: No confirmed in-the-wild exploitation reported at time of writing; vendor advisory published 2026-06-09
- Technical detail: Two critical vulnerabilities allow an unauthenticated remote attacker to execute arbitrary code with administrator privileges and to gain administrator rights on the affected device. Ivanti products have been a persistent target for state-sponsored and ransomware actors throughout 2025-2026.
- Remediation: Apply Ivanti patches immediately per the vendor advisory. Isolate Sentry appliances from untrusted networks pending patching. Review access logs for anomalous authentication attempts. Reference: CERT-EU 2026-008, BSI WID-SEC-2026-1841.
CVE-2026-20253 (Splunk Enterprise / Splunk Cloud Platform)
- Affected products: Splunk Enterprise below 10.2.4 and 10.0.7; Splunk Cloud Platform below 10.4.2604.3 and 10.2.2510.14
- Severity: Critical (CVSS 9.8)
- Exploitation status: No confirmed exploitation; published 2026-06-10 (SVD-2026-0603)
- Technical detail: An unauthenticated attacker reachable over the network can create or truncate arbitrary files via an unauthenticated PostgreSQL sidecar service endpoint. File truncation of critical system files can cause denial of service or facilitate further compromise. The complete absence of authentication controls on this endpoint makes exploitation trivial.
- Remediation: Upgrade Splunk Enterprise to 10.2.4 or 10.0.7. Splunk Cloud Platform customers should verify their instance is on a patched version. Restrict network access to Splunk infrastructure to authorized management hosts. Reference: SVD-2026-0603.
CVE-2026-20251 (Splunk Enterprise / Splunk Cloud Platform / Splunk Secure Gateway)
- Affected products: Splunk Enterprise below 10.2.4, 10.0.7, 9.4.12, 9.3.13; Splunk Cloud Platform below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, 9.3.2411.132; Splunk Secure Gateway below 3.10.6, 3.9.20, 3.8.67
- Severity: High (CVSS 8.8)
- Exploitation status: No confirmed exploitation; published 2026-06-10 (SVD-2026-0601)
- Technical detail: A low-privileged user without admin or power roles can achieve remote code execution via unsafe deserialization of KV Store data through the jsonpickle Python library in the Splunk Secure Gateway app. Arbitrary Python objects are reconstructed from attacker-controlled JSON without validation.
- Remediation: Upgrade to patched versions listed above. If immediate upgrade is not possible, consider disabling the Splunk Secure Gateway app. Reference: SVD-2026-0601.
CVE-2026-5027 (Langflow - ACTIVELY EXPLOITED, UNPATCHED)
- Affected products: Langflow (open-source AI application builder; no patch available at time of reporting)
- Severity: High (CVSS 8.8)
- Exploitation status: Actively exploited in the wild per VulnCheck; no patch available
- Technical detail: A path traversal vulnerability in the POST endpoint allows an unauthenticated attacker to write files to arbitrary locations on the server. Successful exploitation can lead to code execution. Langflow instances are frequently exposed to the internet in development and AI pipeline environments.
- Remediation: No patch available. Immediately restrict Langflow instances to trusted networks only; do not expose to the internet. Monitor for unexpected file creation events. Apply vendor patch as soon as released.
CVE-2026-25089 (Fortinet FortiSandbox)
- Affected products: FortiSandbox, FortiSandbox Cloud, FortiSandbox PaaS WEB UI (versions per vendor advisory)
- Severity: Critical (CVSS 9.1)
- Exploitation status: No confirmed exploitation; patched 2026-06-10
- Technical detail: A command injection vulnerability in the FortiSandbox WEB UI allows an unauthenticated remote attacker to execute arbitrary OS commands. BSI advisory WID-SEC-2026-1836 covers this.
- Remediation: Apply Fortinet security update immediately. Reference: BSI WID-SEC-2026-1836.
CVE-2026-NETLOGON (Windows Netlogon - STATUS CHANGE: Active Exploitation Confirmed)
- Previously reported as no confirmed exploitation. CERT-EU advisory 2026-007 now confirms active exploitation by threat actors per the Centre for Cybersecurity Belgium (CCB). Affects Windows Server acting as a domain controller; allows unauthenticated network RCE. Apply June 2026 Patch Tuesday updates to all domain controllers immediately if not already done.
Microsoft Defender RoguePlanet Zero-Day (STATUS CHANGE: Public PoC Released)
- A public proof-of-concept exploit has been released by researcher Chaotic Eclipse (aka Nightmare-Eclipse) for a race condition vulnerability in Microsoft Defender dubbed RoguePlanet. The PoC grants SYSTEM-level access on fully patched Windows systems. No CVE assigned at time of reporting; no patch available. Exploitation requires local access. Monitor for unusual SYSTEM-level process spawning from Defender-related processes. Confidence: based on researcher disclosure; Microsoft response pending.
CVE-2025-6254 (WordPress Doctreat Core Plugin)
- Affected products: Doctreat Core plugin for WordPress, all versions up to and including 1.6.8
- Severity: Critical (CVSS 9.8)
- Exploitation status: No confirmed exploitation; published 2026-06-10
- Technical detail: The doctreat_process_registration() function does not restrict user roles during registration, allowing unauthenticated attackers to register as administrator. Immediate full site compromise is possible.
- Remediation: Update Doctreat Core plugin to a patched version or disable the plugin until a patch is available. Audit existing user accounts for unauthorized administrator registrations.
CVE-2026-52751 / CVE-2026-52754 / CVE-2026-49498 / CVE-2026-52750 (NSA Ghidra - CONSOLIDATED)
- Affected products: Ghidra before 12.1 (NSA reverse engineering tool)
- Severity: High (CVSS 8.8 / 8.8 / 8.8 / 7.8)
- Exploitation status: No confirmed exploitation; published 2026-06-10
- Technical detail: Four vulnerabilities disclosed. CVE-2026-52751: unauthenticated RCE via unsafe deserialization in Shared-Project RMI connection using a Jython 2.7.4 gadget chain when opening a malicious ghidra:// project file. CVE-2026-52754: authentication bypass via null signature in PKIAuthenticationModule allowing user impersonation with a valid CA-signed certificate. CVE-2026-49498: SQL injection in changePassword() via unescaped usernames enabling PostgreSQL superuser escalation. CVE-2026-52750: command injection via URL annotation clicks on Windows. These are particularly relevant for security research teams and government/defense organizations using Ghidra for malware analysis.
- Remediation: Upgrade to Ghidra 12.1. Do not open untrusted Ghidra project files. Restrict Ghidra server access to trusted users.
ONGOING
- CVE-2026-50751 (Check Point Security Gateway): Actively exploited IKEv1 auth bypass; CISA deadline 2026-06-11, apply hotfix sk185033 immediately.
- CVE-2026-44963 (Veeam Backup and Replication): Critical authenticated RCE; apply June 2026 patch, restrict domain user access.
- CVE-2026-48303 (Adobe Campaign Classic): Critical CVSS 10.0 unauthenticated RCE; apply APSB26-66.
- CVE-2026-47928 et al. (Adobe ColdFusion): Critical/High RCE cluster; apply APSB26-64.
- CVE-2026-45657 / CVE-2026-47291 / CVE-2026-44815 / CVE-2026-42904 (Windows Kernel/HTTP.sys/DHCP/TCP-IP): Critical network-exploitable flaws; apply June 2026 Patch Tuesday.
- CVE-2026-45504 / CVE-2026-45648 (Exchange Server / Active Directory): High-severity; apply June 2026 Patch Tuesday.
- CVE-2026-11645 (Google Chrome V8): Actively exploited; update to 149.0.7827.103 or later.
- CVE-2026-42271 (BerriAI LiteLLM): Actively exploited command injection; CISA deadline 2026-06-22, upgrade to v1.83.7-stable.
- CVE-2026-23111 (Linux Kernel nf_tables): Public working exploit; patch all Linux systems.
- CVE-2026-20245 (Cisco Catalyst SD-WAN Manager): Actively exploited; apply vendor patch.
- CVE-2026-27671 / CVE-2026-44748 / CVE-2026-40128 (SAP NetWeaver): Critical; apply June 2026 SAP Security Notes.
- CVE-2026-46746 / CVE-2026-46748 (Siemens SINEC INS): High; update to V1.0 SP2 Update 6.
EUROPEAN ADVISORIES
BSI CERT-Bund - New Advisories (2026-06-10)
WID-SEC-2026-1870 (NEW): The BSI has published a new high-severity advisory for the Linux Kernel covering multiple vulnerabilities that allow an attacker to cause denial-of-service conditions or conduct other unspecified attacks. Organizations should apply current Linux kernel security updates across all distributions.
WID-SEC-2026-1864 (NEW): New high-severity advisory for Lenovo ThinkPad computers. An attacker on an adjacent network can exploit multiple vulnerabilities to execute arbitrary code and cause denial of service. This is relevant for organizations with large Lenovo ThinkPad deployments, common in German enterprise environments. Apply Lenovo firmware and driver updates per vendor guidance.
WID-SEC-2026-1863 (NEW): New high-severity advisory for Adobe Dreamweaver covering multiple vulnerabilities enabling arbitrary code execution and information disclosure by an unauthenticated remote attacker. Apply Adobe Dreamweaver security updates.
WID-SEC-2026-1860 (NEW): New high-severity advisory for vllm, an open-source LLM inference engine. An unauthenticated remote attacker can execute arbitrary code with administrator privileges. Organizations deploying vllm in AI inference pipelines should apply available patches immediately and restrict network exposure.
WID-SEC-2026-1859 (NEW): New high-severity advisory for AMD ARM and EPYC processors covering multiple vulnerabilities allowing a local attacker to bypass security controls and manipulate data. Apply AMD microcode and firmware updates per vendor guidance.
WID-SEC-2026-1858 (NEW): New high-severity advisory for Adobe ColdFusion covering multiple vulnerabilities enabling code execution, privilege escalation, security bypass, information disclosure, and XSS. This supplements the ColdFusion cluster reported yesterday; apply APSB26-64 if not already done.
WID-SEC-2026-1857 (NEW): New high-severity advisory for Adobe Experience Manager covering multiple vulnerabilities enabling code execution, XSS, and security bypass. Apply Adobe Experience Manager security updates.
WID-SEC-2026-1855 (NEW): New high-severity advisory for QEMU covering a local privilege escalation vulnerability allowing arbitrary code execution. Apply QEMU updates; relevant for virtualization infrastructure operators.
WID-SEC-2026-1852 (NEW): New high-severity advisory for OpenSSL covering multiple vulnerabilities enabling code execution, security bypass, information disclosure, data manipulation, and denial of service. Apply current OpenSSL updates across all affected systems; OpenSSL is a foundational component in virtually all Linux-based infrastructure.
WID-SEC-2026-1849 (NEW): New high-severity advisory for Microsoft Windows and Windows Server covering multiple vulnerabilities from June 2026 Patch Tuesday enabling privilege escalation, code execution, security bypass, data manipulation, and spoofing. Apply June 2026 Patch Tuesday updates.
WID-SEC-2026-1847 (NEW): New high-severity advisory for Microsoft Office and SharePoint covering multiple vulnerabilities enabling privilege escalation, code execution, spoofing, data manipulation, and information disclosure. Apply June 2026 Patch Tuesday Office updates.
WID-SEC-2026-1846 (NEW): New high-severity advisory for Microsoft Exchange covering multiple vulnerabilities enabling privilege escalation, code execution, spoofing, information disclosure, and data manipulation. Apply June 2026 Patch Tuesday Exchange updates.
WID-SEC-2026-1845 (NEW): New high-severity advisory for Microsoft Developer Tools (Visual Studio Code, ASP.NET, .NET, Visual Studio 2026) covering privilege escalation, data manipulation, information disclosure, and authentication bypass. Apply June 2026 Patch Tuesday updates.
WID-SEC-2026-1844 (NEW): New high-severity advisory for Microsoft Dynamics 365 (On-Premises) covering a privilege escalation vulnerability exploitable by an authenticated remote attacker. Apply June 2026 Patch Tuesday updates.
WID-SEC-2026-1842 (NEW): New high-severity advisory for Microsoft Azure and Azure Stack covering code execution, spoofing, privilege escalation, data manipulation, and information disclosure. Apply available Azure security updates.
WID-SEC-2026-1841 (NEW - CRITICAL): New critical advisory for Ivanti Sentry. See Critical Vulnerabilities section for full details.
WID-SEC-2026-1839 (NEW): New high-severity advisory for Zoom Video Communications Workplace covering multiple privilege escalation vulnerabilities exploitable by an unauthenticated remote attacker. Apply Zoom security updates.
WID-SEC-2026-1836 (NEW): New high-severity advisory for Fortinet FortiSandbox (CVE-2026-25089). See Critical Vulnerabilities section.
CERT-EU - New Advisories (2026-06-10)
CERT-EU 2026-008 (NEW): Critical advisory for Ivanti Sentry. Two critical vulnerabilities allow unauthenticated remote code execution. Published 2026-06-10. Apply Ivanti patches immediately.
CERT-EU 2026-007 (STATUS CHANGE): Windows Netlogon critical RCE now confirmed actively exploited by threat actors per the Centre for Cybersecurity Belgium. Domain controllers must be