Joomla Content Editor · Microsoft Defender · Google Android 17
DAILY THREAT INTELLIGENCE BRIEFING Date: 2026-06-17 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership
EXECUTIVE SUMMARY
CISA has added CVE-2026-48907, a maximum-severity improper access control flaw in the Joomla Content Editor (JCE) plugin, to the KEV catalog with a remediation deadline of 2026-06-19. A coordinated supply chain attack has compromised 144 Mastra npm packages via a hijacked contributor account, and 15 malicious JetBrains Marketplace plugins are actively exfiltrating AI API keys from developer environments. Google’s Android 17 launch includes a batch of critical security patches. A Microsoft Defender zero-day (RoguePlanet) remains unpatched.
CRITICAL VULNERABILITIES
CVE-2026-48907 (Widget Factory Joomla Content Editor)
- Affected products: Joomla Content Editor (JCE) plugin for Joomla CMS
- Severity: CVSS 10.0
- EPSS: Not yet scored
- Technical detail: An improper access control flaw allows unauthenticated remote attackers to create new editor profiles, which can be leveraged to upload and execute arbitrary PHP code on the underlying web server. No authentication is required, making this trivially exploitable against any internet-facing Joomla installation running the JCE plugin. Successful exploitation yields remote code execution with web server process privileges, enabling full site compromise, data exfiltration, or use as a pivot point into internal networks.
- Exploitation status: Actively exploited in the wild. Added to CISA KEV 2026-06-16. CISA remediation deadline: 2026-06-19.
- Remediation: Update the JCE plugin to the latest patched version immediately. Audit Joomla installations for unauthorized file uploads, new editor profiles, and PHP webshells. Restrict file upload directories and review web server logs for POST requests to JCE endpoints.
Microsoft Defender / Malware Protection Engine (RoguePlanet zero-day)
- Affected products: Microsoft Defender, Microsoft Malware Protection Engine
- Severity: High (CVSS not yet published); BSI advisory WID-SEC-2026-1976 rated hoch; marked UNGEPATCHT
- EPSS: Not yet scored
- Technical detail: A local privilege escalation zero-day, publicly named RoguePlanet, affects the Microsoft Malware Protection Engine and Microsoft Defender. The vulnerability was disclosed one week ago and Microsoft has confirmed it is working on a patch. A local attacker can exploit the flaw to elevate privileges on affected systems. The attack surface is broad given Defender’s near-universal deployment across Windows enterprise environments. No patch is currently available.
- Exploitation status: Disclosed publicly; no confirmed in-the-wild exploitation reported at time of writing. Patch not yet available.
- Remediation: No vendor patch available. Apply compensating controls: restrict local user privileges, monitor for anomalous Defender process behavior, and apply application control policies where feasible. Monitor Microsoft Security Response Center for patch availability and apply immediately upon release.
Android 17 Security Patches (June 2026 Pixel Patchday)
- Affected products: Google Android 17 (Pixel devices); BSI advisory WID-SEC-2026-1980
- Severity: Multiple CVSS 10.0 entries across privilege escalation, information disclosure, and DoS classes
- EPSS: 0.00 (newly published, no exploitation observed)
- Technical detail: Google’s Android 17 launch includes a large batch of security fixes. Notable CVEs include: CVE-2026-0063 (carrier restriction bypass via logic error, local privilege escalation), CVE-2026-28587 (missing permission check in MmsSmsProvider enabling local information disclosure), CVE-2026-28576 (SQL injection in Contacts Provider), CVE-2026-28615 (unauthorized phone call initiation via permissions bypass), and CVE-2026-0083 (NFC use-after-free race condition enabling local privilege escalation). All are rated CVSS 10.0 by Google. Exploitation requires local access or a malicious app; no additional privileges are needed for most issues.
- Exploitation status: No confirmed exploitation. Newly published with Android 17 release.
- Remediation: Apply the Android 17 security update to Pixel devices. Enterprise MDM administrators should push the update and verify compliance. Review app permission policies for NFC and telephony access.
CVE-2026-48616 (Rocket.Chat)
- Affected products: Rocket.Chat versions prior to 7.10.13, 7.13.9, 8.0.7, 8.1.6, 8.2.6, 8.3.6, 8.4.4, 8.5.1
- Severity: CVSS 9.3
- EPSS: 0.00 (newly published)
- Technical detail: An access control vulnerability in the Livechat file download handler allows unauthenticated access to protected file uploads. The /file-upload/:fileId/:name endpoint does not properly enforce authorization, meaning any unauthenticated actor who can enumerate or guess file identifiers can retrieve files shared in Livechat conversations. This affects a broad range of Rocket.Chat versions across multiple maintained branches and is relevant to organizations using Rocket.Chat as an enterprise messaging or customer support platform.
- Exploitation status: No confirmed exploitation. Newly published.
- Remediation: Upgrade Rocket.Chat to a patched version per your branch (see affected version list above). Review Livechat file upload logs for unauthorized access. Restrict Rocket.Chat instance exposure to trusted networks where possible.
CVE-2026-25470 (ACPT Pro - Custom Post Types Plugin for WordPress)
- Affected products: ACPT (Pro) Custom Post Types Plugin for WordPress, versions up to and including 2.0.47
- Severity: CVSS 10.0
- EPSS: 0.00 (newly published)
- Technical detail: A remote code inclusion vulnerability allows unauthenticated attackers to inject and execute arbitrary code via the plugin’s code generation functionality. This is a critical unauthenticated RCE affecting WordPress sites running the ACPT Pro plugin. Given the broad deployment of WordPress in European enterprise and public sector web environments, this warrants immediate attention.
- Exploitation status: No confirmed exploitation. Newly published.
- Remediation: Update ACPT Pro to a version above 2.0.47 immediately. If no patch is available, deactivate the plugin until a fix is released. Audit WordPress installations for signs of compromise.
ONGOING
- CVE-2026-20262 (Cisco Catalyst SD-WAN Manager): Actively exploited zero-day; CISA KEV deadline 2026-06-29; patch immediately.
- CVE-2026-0257 (Palo Alto PAN-OS GlobalProtect): Actively exploited authentication bypass; apply PAN-OS patches without delay.
- CVE-2026-54420 (LiteSpeed cPanel Plugin): CISA KEV deadline 2026-06-18 today; patch to cPanel plugin 2.4.8 and WHM Plugin 5.3.2.0 immediately.
- CVE-2026-42271 (LiteLLM): KEV deadline 2026-06-22; upgrade to v1.83.7-stable.
- CVE-2026-5027 (Langflow): Actively exploited; isolate from internet.
- CVE-2026-50751 (Check Point Security Gateway): Actively exploited; apply hotfix sk185033.
- CVE-2026-11645 (Google Chrome V8): Actively exploited; update to 149.0.7827.103 or later.
EUROPEAN ADVISORIES
BSI published a high volume of update advisories on 2026-06-17 covering Linux Kernel (multiple advisories across kernel versions), Red Hat OpenShift (code execution and security bypass), Splunk Enterprise, Golang Go, Mozilla Firefox and Thunderbird, and Android Patchday December 2025. Apply vendor patches per prior guidance. The Android 17 Pixel Patchday (WID-SEC-2026-1980) is detailed in the Critical Vulnerabilities section.
WID-SEC-2026-1976 (Microsoft Malware Protection Engine / Defender RoguePlanet): Covered in Critical Vulnerabilities.
WID-SEC-2026-1836 / WID-SEC-2026-1094 (Fortinet FortiSandbox): BSI updated two critical advisories covering unauthenticated OS command execution and multiple additional vulnerabilities including XSS, information disclosure, and security bypass. Organizations running FortiSandbox should apply the latest Fortinet security updates immediately and review sandbox management interface exposure.
WID-SEC-2026-1349 (vm2): Updated critical advisory covering arbitrary code execution, DoS, information disclosure, and security bypass in the vm2 JavaScript sandbox library. vm2 is used in Node.js environments for sandboxed code execution; organizations should migrate away from vm2 (the project is abandoned) or apply available mitigations.
WID-SEC-2026-1975 / WID-SEC-2026-1974 / WID-SEC-2026-1970 (LiteLLM, vllm, Langflow): BSI published new high-severity advisories for three AI infrastructure components. LiteLLM and vllm allow unauthenticated remote attackers to bypass security controls; Langflow allows DoS and information disclosure. Organizations deploying AI/LLM infrastructure should apply available updates and restrict management interface exposure. Note: Langflow CVE-2026-5027 remains actively exploited per prior reporting.
WID-SEC-2026-1824 (Apache HTTP Server): Updated high-severity advisory covering code execution, security bypass, XSS, data manipulation, and DoS. Apply the latest Apache HTTP Server release.
ACTIVE THREATS AND CAMPAIGNS
Mastra npm Supply Chain Attack (easy-day-js): A hijacked npm contributor account (ehindero) was used to mass-publish malicious versions of 144 packages in the @mastra namespace, a popular JavaScript/TypeScript AI application framework. The attack, codenamed easy-day-js, was identified by JFrog, SafeDep, Socket, and StepSecurity. Organizations using Mastra packages should audit their dependency trees, rotate any secrets or tokens present in environments where affected packages were installed, and lock package versions. This is a high-impact supply chain event for development teams.
Malicious JetBrains Marketplace Plugins: At least 15 plugins published to the JetBrains Marketplace pose as AI coding assistants (DeepSeek and similar LLMs) and exfiltrate AI provider API keys (OpenAI, DeepSeek, and others) to external attacker-controlled servers. The campaign is described as coordinated. Development teams using JetBrains IDEs should audit installed plugins, remove any recently installed AI assistant plugins not from verified publishers, and rotate all AI API keys as a precaution.
Rokarolla Android Banking Trojan: A newly documented Android banking trojan targets 217 banking and cryptocurrency applications with 137 remote commands. Capabilities include PIN theft, SMS interception, clipboard hijacking for cryptocurrency address substitution, and disabling Google Play Protect. Relevant to organizations with BYOD policies or mobile banking exposure. Enforce MDM policies and monitor for sideloaded applications.
ClickFix Campaign Expansion: Ongoing ClickFix campaigns now deliver three new loaders — BabaDeda, Lorem Ipsum, and Potemkin — via fake browser update lures. BabaDeda has targeted education and financial organizations since April 2026. Block PowerShell execution from browser processes and enforce application allowlisting.
Steam Workshop Malware Distribution: Threat actors are embedding malware in wallpaper packages distributed via Steam Workshop through the Wallpaper Engine application. Relevant to organizations where Steam is accessible on endpoints. Enforce application allowlisting and restrict Steam Workshop content.
ONGOING: China-linked REDCap espionage campaign — audit REDCap servers and Google Workspace forwarding rules; rotate credentials. ONGOING: North Korean Contagious Interview developer lure campaign — brief development staff on recruitment-themed lures. ONGOING: ShinyHunters Oracle PeopleSoft exploitation — patch PeopleSoft and monitor for extortion contact.
SECURITY NEWS AND CONTEXT
Novo Nordisk Data Breach: A cybercriminal group has stolen sensitive data from Novo Nordisk (manufacturer of Ozempic); the incident is under investigation. European pharmaceutical sector organizations should review threat exposure.
Kodak Data Breach: Kodak confirmed a data breach claimed by the ShinyHunters extortion group; external forensic investigation is underway.
Oracle Critical Patch Update: Oracle released 245 security updates in its quarterly CPU. Organizations should prioritize Oracle Database, WebLogic, and PeopleSoft patches given active ShinyHunters exploitation of PeopleSoft.
FBI Takedown of Outsider PhaaS: The FBI dismantled the Outsider Phishing-as-a-Service platform, which operated across thousands of domains and stole millions of payment card records.
RECOMMENDED ACTIONS
- Patch Joomla JCE plugin (CVE-2026-48907) immediately — CISA KEV deadline 2026-06-19; audit for webshells and unauthorized file uploads.
- Apply compensating controls for Microsoft Defender RoguePlanet zero-day — no patch available; restrict local user privileges and monitor Defender process activity.
- Audit all @mastra npm packages in dependency trees; rotate secrets from affected build environments.
- Remove unverified AI assistant plugins from JetBrains IDEs and rotate all AI provider API keys.
- Upgrade Rocket.Chat to a patched branch version to remediate CVE-2026-48616 unauthenticated file access.
- Update ACPT Pro WordPress plugin beyond version 2.0.47 or deactivate pending patch availability.
- Apply Android 17 security updates to Pixel devices via MDM; review NFC and telephony app permissions.
- Apply Fortinet FortiSandbox updates per BSI WID-SEC-2026-1836 and WID-SEC-2026-1094; restrict management interface access.
- Apply Oracle Critical Patch Update, prioritizing PeopleSoft and WebLogic given active exploitation by ShinyHunters.
- Continue remediation of previously reported items: Cisco SD-WAN CVE-2026-20262, PAN-OS CVE-2026-0257, LiteSpeed CVE-2026-54420 (deadline today), LiteLLM CVE-2026-42271, Langflow CVE-2026-5027, Check Point CVE-2026-50751, Chrome CVE-2026-11645.