LiteSpeed cPanel plugin · GL.iNet GL-MT3000 · Ruijie EG105G-P firmware
DAILY THREAT INTELLIGENCE BRIEFING Date: 2026-06-15 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership
EXECUTIVE SUMMARY
The Oracle PeopleSoft CVE-2026-35273 CISA KEV remediation deadline expires today; any unfederal agency or organization treating this as a benchmark must patch immediately. New items today include a LiteSpeed cPanel plugin symlink vulnerability exploited in the wild since May 2026, two command injection flaws in GL.iNet routers with public exploits, and a critical Ruijie router command injection. The FBI and Google have jointly dismantled the Outsider Enterprise Chinese phishing-as-a-service operation. No new BSI or CERT-EU advisories were published in the last 24 hours.
CRITICAL VULNERABILITIES
CVE-2026-54420 (LiteSpeed cPanel Plugin)
- Affected products: LiteSpeed cPanel plugin before 2.4.8; LiteSpeed WHM Plugin before 5.3.2.0
- Severity: CVSS 8.5
- EPSS: 0.00 (exploitation confirmed in wild — EPSS lags confirmation)
- Technical detail: The plugin mishandles symlinks supplied by a user with FTP or web shell access on shared hosting servers running CloudLinux/CageFS. An attacker with low-privilege FTP or web shell access can craft symlinks to escape the CageFS container and read or write files outside their designated directory, potentially accessing other tenants’ data or escalating to server-level compromise. The vulnerability is particularly impactful on shared hosting infrastructure where multiple tenants coexist on a single host.
- Exploitation status: Confirmed exploited in the wild as of May 2026. This is a STATUS CHANGE from yesterday — exploitation confirmation elevates priority.
- Remediation: Update LiteSpeed cPanel plugin to 2.4.8 or later and LiteSpeed WHM Plugin to 5.3.2.0 or later immediately. Audit symlink handling and CageFS configurations on affected shared hosting servers. Review access logs for anomalous cross-tenant file access patterns.
CVE-2026-12187 and CVE-2026-12186 (GL.iNet GL-MT3000 Router)
- Affected products: GL.iNet GL-MT3000 versions 4.4.0 through 4.4.5
- Severity: CVSS 8.7 (both)
- EPSS: 0.00 — public exploit available
- Technical detail: Two distinct command injection vulnerabilities affect the GL-MT3000 travel router. CVE-2026-12187 resides in the /usr/bin/one_click_upgrade Online Firmware Upgrade Handler; CVE-2026-12186 affects the replace_country function in the Tor Proxy Service Configuration Handler (/usr/lib/oui-httpd/rpc/tor). Both are remotely exploitable without authentication and have public exploits. GL.iNet travel routers are commonly deployed in enterprise remote-access and field scenarios, making them a viable pivot point into corporate networks.
- Exploitation status: No confirmed in-the-wild exploitation; public exploits available, raising near-term risk significantly.
- Remediation: Upgrade GL-MT3000 firmware to version 4.7 or later. Where immediate upgrade is not possible, disable remote management interfaces and restrict administrative access to trusted local networks only.
CVE-2026-12197 (Ruijie EG105G-P Router)
- Affected products: Ruijie EG105G-P firmware version 2.340
- Severity: CVSS 8.6
- EPSS: 0.00 — public exploit available
- Technical detail: The nslookup function in the JSON-RPC Diagnose Endpoint (/cgi-bin/luci/api/diagnose) does not sanitize the params.target argument, allowing remote unauthenticated attackers to inject arbitrary OS commands. The exploit has been publicly released. Ruijie networking equipment is deployed across enterprise and SMB environments, particularly in Asia-Pacific regions, but also present in European branch office deployments.
- Exploitation status: No confirmed in-the-wild exploitation; public exploit available.
- Remediation: Apply vendor firmware update when available. Immediately restrict access to the diagnostic API endpoint via firewall rules. Disable remote management if not operationally required.
ONGOING
- CVE-2026-35273 (Oracle PeopleSoft): CISA KEV deadline is today, 2026-06-15 — patch without exception; audit logs for May 27 to June 9 window.
- CVE-2026-20253 (Splunk Enterprise): Update to 10.2.4 or 10.0.7; restrict management interfaces.
- CVE-2026-12183 (BUK TS-G Gas Station Automation): Isolate from untrusted networks; enforce firewall controls.
- CVE-2026-11624 (Google MCP Toolbox): Update to v0.25.0; configure allowed-hosts and allowed-origins.
- CVE-2026-9848 (WP Ticket WordPress plugin): Update or disable; monitor WAF logs.
- CVE-2026-10520 (Ivanti Sentry): KEV deadline passed; patch immediately if not done.
- CVE-2026-5027 (Langflow): Actively exploited; isolate from internet.
- CVE-2026-50751 (Check Point Security Gateway): Actively exploited; apply hotfix sk185033.
- CVE-2026-11645 (Google Chrome V8): Actively exploited; update to 149.0.7827.103 or later.
- CVE-2026-42271 (BerriAI LiteLLM): KEV deadline 2026-06-22; upgrade to v1.83.7-stable.
EUROPEAN ADVISORIES
No new BSI WID or CERT-EU advisories were published in the last 24 hours.
Previously reported advisories remain open. The Tchap breach affecting over 73,000 French government employees (reported 2026-06-12) is relevant to European public sector organizations; French authorities are investigating. Organizations using Tchap or similar government-operated messaging platforms should review account security and monitor for credential exposure. All prior BSI advisories covering rclone, MongoDB, IBM i, VMware Tanzu Spring Cloud Gateway, Langflow, Google Chrome, and OpenClaw remain open; apply vendor patches per prior guidance.
ACTIVE THREATS AND CAMPAIGNS
Outsider Enterprise PhaaS Dismantled (STATUS CHANGE): The FBI, working with Google and Black Lotus Labs, has dismantled the Outsider Enterprise Chinese phishing-as-a-service operation, which operated approximately one million phishing URLs targeting credit card data and passwords. This expands on the Google lawsuit reported yesterday; the infrastructure takedown is now confirmed. Organizations should continue monitoring for residual phishing activity as threat actors may reconstitute infrastructure under new domains. Review email gateway and DNS filtering rules for any previously identified Outsider-associated indicators.
Arch Linux AUR Supply Chain Attack — ONGOING: Over 400 packages remain implicated; audit AUR builds and CI/CD pipelines for Rust infostealer and eBPF rootkit indicators.
Velvet Ant Linux PAM/OpenSSH Backdoor — ONGOING: Audit PAM module integrity and OpenSSH binary hashes on sensitive Linux systems.
SECURITY NEWS AND CONTEXT
Outsider Enterprise takedown: The FBI, Google, and Black Lotus Labs jointly dismantled the Chinese Outsider Enterprise phishing-as-a-service platform, which used approximately one million URLs and leveraged Gemini AI to craft phishing messages. This consolidates the Google lawsuit and FBI action into a single confirmed disruption event.
phpBB authentication bypass: A decade-old authentication bypass in phpBB forum software has been patched; the flaw allowed login as any user including administrators. Organizations running phpBB should apply the update immediately.
Novo Nordisk clinical trial data breach: Danish pharmaceutical giant Novo Nordisk disclosed a breach affecting patient data from clinical trials. European healthcare organizations should review third-party data processor security postures.
RECOMMENDED ACTIONS
- Patch Oracle PeopleSoft CVE-2026-35273 today — CISA KEV deadline is 2026-06-15. Audit logs for the May 27 to June 9 window without delay.
- Update LiteSpeed cPanel plugin to 2.4.8 and WHM Plugin to 5.3.2.0 immediately — CVE-2026-54420 is confirmed exploited in the wild on shared hosting infrastructure.
- Upgrade GL.iNet GL-MT3000 firmware to version 4.7 to address CVE-2026-12187 and CVE-2026-12186; disable remote management on unpatched devices.
- Restrict or disable the Ruijie EG105G-P diagnostic API endpoint (CVE-2026-12197) via firewall rules pending vendor firmware update.
- Update phpBB to the latest patched release to address the decade-old authentication bypass.
- Review email gateway and DNS filtering rules for residual Outsider Enterprise phishing infrastructure indicators following the FBI/Google takedown.
- European healthcare organizations should assess third-party data processor security controls in light of the Novo Nordisk clinical trial data breach.
- Audit AUR-sourced packages and CI/CD pipelines for Rust infostealer and eBPF rootkit indicators (Arch Linux AUR supply chain attack).
- Continue remediation of previously reported items: Splunk CVE-2026-20253, Ivanti Sentry CVE-2026-10520, Langflow CVE-2026-5027, Check Point CVE-2026-50751, Chrome CVE-2026-11645, LiteLLM CVE-2026-42271, BUK TS-G CVE-2026-12183, MCP Toolbox CVE-2026-11624, WP Ticket CVE-2026-9848.