← All briefings

Splunk Enterprise · BUK TS-G Gas Station Automation System · MCP Toolbox for Databases

DAILY THREAT INTELLIGENCE BRIEFING Date: 2026-06-14 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership

EXECUTIVE SUMMARY

Today’s most significant new item is a critical unauthenticated remote code execution vulnerability in Splunk Enterprise (CVE-2026-20253, CVSS 9.8), which allows arbitrary file operations and code execution without authentication against widely deployed enterprise SIEM infrastructure. Additionally, a critical authentication bypass in a gas station automation system (CVE-2026-12183, CVSS 9.3) exposes industrial control systems to unauthenticated administrative access. The Oracle PeopleSoft CISA KEV remediation deadline of 2026-06-15 is now less than 24 hours away.

CRITICAL VULNERABILITIES

CVE-2026-20253 (Splunk Enterprise)

  • Affected products: Splunk Enterprise versions below 10.2.4 and 10.0.7
  • Severity: CVSS 9.8
  • EPSS: Not yet available
  • Technical detail: An unauthenticated attacker can trigger arbitrary file creation or truncation on the Splunk Enterprise host, with the vulnerability chain enabling full remote code execution. No authentication is required, making this exploitable from any network-reachable position. Splunk Enterprise is deployed extensively as a SIEM and log aggregation platform across enterprise and critical infrastructure environments. The combination of unauthenticated access and RCE capability makes this a high-priority target for ransomware operators and espionage actors seeking to blind or subvert security monitoring.
  • Exploitation status: No confirmed in-the-wild exploitation at time of writing; given the CVSS 9.8 rating and unauthenticated attack vector, exploitation attempts are expected rapidly.
  • Remediation: Update Splunk Enterprise to version 10.2.4 or 10.0.7 or later immediately. Where immediate patching is not possible, restrict Splunk management interfaces to trusted network segments and enforce firewall controls. Monitor Splunk logs for anomalous file creation events.

CVE-2026-12183 (Nefteprodukttekhnika BUK TS-G Gas Station Automation System)

  • Affected products: BUK TS-G Gas Station Automation System versions 2.9.1 through 2.10.2 on Linux
  • Severity: CVSS 9.3
  • EPSS: 0.00 — no exploitation observed
  • Technical detail: The /php/ajax-login.php endpoint returns administrator-level session data (userid=1) in response to any HTTP POST request with arbitrary credentials, effectively bypassing authentication entirely. Subsequent privileged endpoints under /php/ajax-main.php and /modules/* perform no server-side session validation. A remote unauthenticated attacker can invoke any administrative function, including reading and modifying fuel tank gauges, dispensers, pricing rules, cash registers, bank terminals, and fuel card data. This is an OT/ICS-adjacent system; exploitation could enable fuel theft, financial fraud, or physical process manipulation at affected sites.
  • Exploitation status: No confirmed exploitation; public advisory published 2026-06-13.
  • Remediation: Immediately isolate affected systems from internet-facing and untrusted network segments. Apply vendor patches when available. Enforce network-level access controls restricting the web management interface to authorized maintenance hosts only. Audit logs for unauthorized administrative actions.

CVE-2026-11624 (Google MCP Toolbox for Databases)

  • Affected products: MCP Toolbox for Databases versions prior to 0.25.0
  • Severity: CVSS 9.4
  • EPSS: 0.01
  • Technical detail: Prior to v0.25.0, the Model Context Protocol server performed no validation of the HTTP Origin header on incoming connections, leaving it fully exposed to DNS rebinding attacks. An attacker who can cause a victim’s browser to make requests to a locally running MCP server can pivot to interact with backend databases as if they were a trusted local client. The v0.25.0 release introduces –allowed-hosts and –allowed-origins flags; both default to wildcard, meaning deployments must be explicitly reconfigured to enforce restrictions. MCP Toolbox is used in AI agent and LLM-integrated database access workflows, which are increasingly common in enterprise environments.
  • Exploitation status: No confirmed exploitation; patch available.
  • Remediation: Update MCP Toolbox for Databases to v0.25.0 or later. Configure –allowed-hosts and –allowed-origins to restrict access to known trusted origins. Do not leave either flag at the default wildcard value in production deployments.

CVE-2026-9848 (WP Ticket / Customer Support Ticket System for WordPress)

  • Affected products: emarket-design Customer Support Ticket System & Helpdesk (WP Ticket) versions up to and including 6.0.4
  • Severity: CVSS 7.5
  • EPSS: 0.08
  • Technical detail: The plugin hooks WordPress’s posts_request filter and concatenates the raw search query parameter directly into a SQL UNION sub-SELECT without using $wpdb->prepare() or any escaping. Because wp_magic_quotes protection is stripped by WP_Query before the plugin processes the value, unauthenticated attackers can inject arbitrary SQL via the front-end search parameter to extract sensitive data from the WordPress database, including credentials and private content.
  • Exploitation status: No confirmed exploitation; unauthenticated attack vector increases risk.
  • Remediation: Update the plugin to a patched version when available. As an interim measure, disable the plugin or restrict front-end search functionality. Monitor web application firewall logs for SQL injection patterns targeting WordPress search endpoints.

ONGOING

  • CVE-2026-35273 (Oracle PeopleSoft): CISA KEV deadline 2026-06-15 — patch today without exception; audit logs for May 27 to June 9 window.
  • CVE-2026-47140 / CVE-2026-47210 / CVE-2026-47139 (vm2): Update to 3.11.4; apply OS-level sandboxing.
  • CVE-2026-45830 cluster (ChromaDB): Isolate multi-tenant deployments; disable trust_remote_code; await vendor patch.
  • CVE-2026-54361 cluster (MISP): Update to 2.5.40; enable Security.check_sec_fetch_site_header.
  • CVE-2026-44168 / CVE-2026-48163 / CVE-2026-48165 (MariaDB Galera): Apply vendor patches; restrict cluster membership.
  • CVE-2026-50084 cluster (Aqara): Isolate devices; rotate developer tokens.
  • CVE-2026-48558 (SimpleHelp): Update to 5.5.16 or later.
  • CVE-2026-10520 (Ivanti Sentry): KEV deadline passed; patch immediately if not done.
  • CVE-2026-5027 (Langflow): Actively exploited; isolate from internet.
  • CVE-2026-50751 (Check Point Security Gateway): Actively exploited; apply hotfix sk185033.
  • CVE-2026-11645 (Google Chrome V8): Actively exploited; update to 149.0.7827.103 or later.
  • CVE-2026-42271 (BerriAI LiteLLM): KEV deadline 2026-06-22; upgrade to v1.83.7-stable.

EUROPEAN ADVISORIES

No new BSI WID or CERT-EU advisories were published in the last 24 hours.

Previously reported advisories remain open: BSI WID-SEC-2026-1811 (rclone) — apply latest rclone release and review automated pipeline exposure. BSI advisories for MongoDB, IBM i, VMware Tanzu Spring Cloud Gateway, Langflow, Google Chrome, and OpenClaw remain open; apply vendor patches per prior guidance.

ACTIVE THREATS AND CAMPAIGNS

Chinese APT — Decade-Long Authentication Stack Compromise (NEW): Bleeping Computer reported that a China-nexus threat actor hijacked a target organization’s authentication infrastructure and maintained persistent access for approximately ten years, with full visibility into administrative activity. The actor is reported to have taken control of the authentication flow itself rather than relying on credential theft alone. This technique enables persistent, low-noise access that survives password resets and account audits. Organizations should audit PAM configurations, authentication middleware integrity, and SSO/IdP components for unauthorized modifications.

Arch Linux AUR Supply Chain Attack — ONGOING: No new IOCs; over 400 packages remain implicated. Audit AUR builds and CI/CD pipelines for Rust infostealer and eBPF rootkit indicators.

Velvet Ant Linux PAM/OpenSSH Backdoor — ONGOING: Audit PAM module integrity and OpenSSH binary hashes on sensitive Linux systems.

SECURITY NEWS AND CONTEXT

Splunk Enterprise RCE (CVE-2026-20253): The Hacker News reported the critical unauthenticated RCE flaw; full details are in the Critical Vulnerabilities section above.

US Government restricts Anthropic AI models: The US government ordered Anthropic to suspend access to Claude Fable 5 and Mythos 5 for foreign nationals worldwide; Anthropic is complying while disputing the basis. Organizations using these models in security tooling or workflows should assess continuity impact.

Former IT employee sentenced: A former Iowa school district IT employee received a 21-month prison sentence for a sustained cyberattack against his former employer, including account deletion and service disruption. Reinforces the need for prompt access revocation upon employee departure.

RECOMMENDED ACTIONS

  1. Patch Oracle PeopleSoft CVE-2026-35273 today — CISA KEV deadline is 2026-06-15. Audit logs for the May 27 to June 9 window without delay.
  2. Update Splunk Enterprise to version 10.2.4 or 10.0.7 immediately; restrict management interfaces to trusted network segments pending patching.
  3. Isolate BUK TS-G Gas Station Automation System (CVE-2026-12183) from untrusted networks; enforce firewall controls on the web management interface.
  4. Update MCP Toolbox for Databases to v0.25.0; explicitly configure –allowed-hosts and –allowed-origins to restrict access.
  5. Update or disable WP Ticket plugin (CVE-2026-9848) on WordPress deployments; monitor WAF logs for SQL injection attempts.
  6. Audit authentication infrastructure components (PAM, SSO, IdP, OpenSSH) for unauthorized modifications in light of the reported decade-long Chinese APT authentication stack compromise.
  7. Enforce immediate access revocation procedures for departing IT staff; review privileged account audit trails.
  8. Continue remediation of previously reported items: Oracle PeopleSoft CVE-2026-35273, vm2 CVE-2026-47140 cluster, ChromaDB CVE-2026-45830 cluster, MISP CVE-2026-54361 cluster, MariaDB Galera CVEs, Ivanti Sentry CVE-2026-10520, Langflow CVE-2026-5027, Check Point CVE-2026-50751, Chrome CVE-2026-11645, LiteLLM CVE-2026-42271.