Splunk Enterprise · NGINX Open Source and NGINX Plus · pgAdmin 4
DAILY THREAT INTELLIGENCE BRIEFING Date: 2026-06-19 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership
EXECUTIVE SUMMARY
The most significant new developments today are the CISA KEV addition of CVE-2026-20253 (Splunk Enterprise missing authentication, due 2026-06-21), a CISA alert and UK NCSC advisory on the FortiBleed credential leak now confirmed at approximately 74,000 devices, critical NGINX RCE flaws patched out-of-band by F5, multiple critical pgAdmin 4 vulnerabilities including SQL injection and stored XSS, and a DragonForce ransomware campaign abusing Microsoft Teams relay infrastructure for C2 concealment. Law enforcement dismantled the SocGholish botnet in a major international operation.
CRITICAL VULNERABILITIES
NEW
CVE-2026-20253 (Splunk Enterprise)
- Affected products: Splunk Enterprise (all versions prior to vendor-specified patch)
- Severity: Not yet CVSS-scored in available data
- EPSS: Not yet scored
- Technical detail: A missing authentication vulnerability in Splunk Enterprise’s PostgreSQL sidecar service endpoint allows an unauthenticated remote attacker to create or truncate arbitrary files on the host filesystem. The sidecar service is exposed without authentication controls, meaning no credentials are required to trigger the file operation. In enterprise deployments where Splunk indexes security telemetry, successful exploitation could corrupt log data, disrupt SIEM operations, or stage further attacks by writing malicious files to accessible paths.
- Exploitation status: Actively exploited — added to CISA KEV 2026-06-18. Federal deadline 2026-06-21.
- Remediation: Apply Splunk-issued patches immediately. Restrict network access to Splunk backend service ports. Audit filesystem for unexpected file creation or truncation events. CISA KEV deadline is 2026-06-21; treat as emergency priority.
CVE-2026-42530 and related (NGINX Open Source / NGINX Plus)
- Affected products: NGINX Open Source and NGINX Plus (all versions through 3.4.0 for HAProxy-related issues; F5 out-of-band patches address NGINX HTTP/3 module flaws)
- Severity: CVSS 9.2 (CVE-2026-42530); additional flaws CVE-2026-55203 CVSS 9.0, CVE-2026-55204 CVSS 8.7
- EPSS: Not yet scored
- Technical detail: CVE-2026-42530 is a use-after-free in the ngx_http_v3_module, triggerable by a remote unauthenticated attacker when HTTP/3 is enabled, potentially leading to RCE. CVE-2026-55203 is an integer overflow in HAProxy’s FCGI connector that allows buffer misparse as new FCGI record headers. CVE-2026-55204 is a null pointer dereference in hpack_dht_insert() that can be triggered remotely. NGINX is among the most widely deployed web servers globally; HTTP/3 adoption is increasing in enterprise environments, broadening the attack surface for CVE-2026-42530.
- Exploitation status: No confirmed in-the-wild exploitation. F5 issued out-of-band patches on 2026-06-18, indicating vendor-assessed urgency.
- Remediation: Apply F5 out-of-band patches immediately. If HTTP/3 is not required, disable the ngx_http_v3_module as a temporary mitigation. Apply HAProxy fixes (commits 5985276 and 9a6d1fe). BSI advisory WID-SEC-2026-1995 covers NGINX; see European Advisories.
CVE-2026-12045 / CVE-2026-12046 / CVE-2026-12044 / CVE-2026-12048 (pgAdmin 4)
- Affected products: pgAdmin 4 versions prior to 9.16
- Severity: CVE-2026-12045 CVSS 9.4 (SQL execution bypass via AI Assistant); CVE-2026-12046 CVSS 9.5 (CSRF on state-mutating endpoints); CVE-2026-12044 CVSS 8.7 (SQL injection in COMMENT ON templates); CVE-2026-12048 CVSS 9.3 (stored XSS in error/plan rendering)
- EPSS: 0.00 (newly published)
- Technical detail: Four distinct vulnerabilities affect pgAdmin 4. CVE-2026-12045 allows an attacker who can influence database content to bypass the read-only transaction restriction in the AI Assistant, executing arbitrary SQL with pgAdmin user privileges. CVE-2026-12046 exposes two state-mutating SQL Editor endpoints without CSRF protection, enabling cross-site request forgery. CVE-2026-12044 is a SQL injection in Jinja templates rendering COMMENT ON statements across multiple object types. CVE-2026-12048 is a stored XSS via PostgreSQL server error messages and plan node text. pgAdmin is the dominant GUI administration tool for PostgreSQL and is widely deployed in enterprise database environments.
- Exploitation status: No confirmed exploitation. Newly published 2026-06-18.
- Remediation: Upgrade pgAdmin 4 to version 9.16 immediately. Restrict pgAdmin access to trusted networks. Disable the AI Assistant feature if not required.
CVE-2026-54130 (Microsoft 365 Copilot)
- Affected products: Microsoft 365 Copilot
- Severity: CVSS 9.8
- EPSS: 0.00 (newly published)
- Technical detail: A missing authentication for critical function vulnerability in Microsoft 365 Copilot allows an unauthenticated remote attacker to disclose information over a network. The specific function affected is not fully detailed in available data, but the CVSS 9.8 score and unauthenticated network attack vector indicate a high-impact exposure in a widely deployed enterprise AI service. Organizations with M365 Copilot licensing should treat this as a priority.
- Exploitation status: No confirmed exploitation. Newly published 2026-06-18.
- Remediation: Apply Microsoft-issued patches or mitigations as released. Monitor Microsoft Security Response Center for guidance. Review Copilot access logs for anomalous information access.
CVE-2026-47647 (Microsoft Dynamics 365)
- Affected products: Microsoft Dynamics 365
- Severity: CVSS 9.9
- EPSS: 0.00 (newly published)
- Technical detail: An improper access control vulnerability in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network. The near-maximum CVSS score reflects the severity of the privilege escalation impact. Dynamics 365 is broadly deployed across European enterprises for ERP and CRM functions, making this a high-priority item for organizations in those sectors.
- Exploitation status: No confirmed exploitation. Newly published 2026-06-18.
- Remediation: Apply Microsoft-issued patches. Review Dynamics 365 user privilege assignments and audit recent privilege changes.
ONGOING
- CVE-2026-20253 (Splunk Enterprise): Actively exploited; CISA KEV deadline 2026-06-21 — patch today.
- CVE-2026-12569 (PTC Windchill PDMLink / FlexPLM): Unpatched RCE via deserialization; BSI advisory WID-SEC-2026-1991 marked UNGEPATCHT; restrict network access.
- CVE-2026-50656 (Microsoft Defender / RoguePlanet): No patch available; restrict local user privileges.
- CVE-2026-48907 (Joomla JCE plugin): CISA KEV deadline was 2026-06-19; verify patch applied and audit for webshells.
- CVE-2026-20262 (Cisco Catalyst SD-WAN Manager): Actively exploited; CISA KEV deadline 2026-06-29; patch immediately.
- CVE-2026-42271 (LiteLLM): KEV deadline 2026-06-22; upgrade to v1.83.7-stable.
- CVE-2026-0257 (Palo Alto PAN-OS GlobalProtect): Actively exploited; apply PAN-OS patches.
- CVE-2026-5027 (Langflow): Actively exploited; isolate from internet.
- CVE-2026-50751 (Check Point Security Gateway): Actively exploited; apply hotfix sk185033.
- CVE-2026-11645 (Google Chrome V8): Actively exploited; update to 149.0.7827.103 or later.
EUROPEAN ADVISORIES
BSI published a large volume of new and updated advisories on 2026-06-18. New critical and high-severity items of note:
WID-SEC-2026-2002 (Drupal Core): Critical advisory covering multiple vulnerabilities enabling arbitrary code execution, XSS, data manipulation, and malicious redirects. Drupal is widely deployed in European public sector and enterprise web environments. Apply Drupal security updates immediately and review for signs of compromise.
WID-SEC-2026-1997 (Widget Factory Joomla Content Editor): Critical advisory for a remote code execution vulnerability exploitable by unauthenticated attackers. Apply vendor patch immediately.
WID-SEC-2026-1991 (PTC FlexPLM / Windchill): Covered in Critical Vulnerabilities. Marked UNGEPATCHT by BSI.
WID-SEC-2026-1995 (NGINX / NGINX Plus): Covered in Critical Vulnerabilities.
WID-SEC-2026-1989 (Cisco ISE / ISE-PIC): New high-severity advisory covering RCE, privilege escalation to administrator, and information disclosure in Cisco Identity Services Engine. Cisco ISE is a core network access control component in many European enterprise environments. Apply Cisco patches and review ISE administrator activity.
WID-SEC-2026-1990 (Mitel MiCollab): New high-severity advisory covering RCE, security bypass, SQL injection, data manipulation, and information disclosure. Apply Mitel updates.
WID-SEC-2026-1986 (iba AG ibaPDA): New high-severity advisory for a deserialization RCE vulnerability (CVE-2026-8024) in ibaPDA and ibaDatCoordinator. Relevant to organizations with OT/IT convergence. Upgrade to ibaPDA 8.14.0 and ibaDatCoordinator 4.0.7.
WID-SEC-2026-2001 (IBM WebSphere Application Server): New high-severity advisory covering RCE, DoS, security bypass, information disclosure, and privilege escalation. Apply IBM patches.
WID-SEC-2026-1993 (Android June 2026 Patchday): New high-severity advisory for multiple Android vulnerabilities including privilege escalation and RCE. Apply June 2026 Android security updates.
WID-SEC-2026-1996 (libssh2): Update to previously reported advisory; apply upstream patches per prior guidance.
Updated advisories for Apache HTTP Server (WID-SEC-2026-1824), Linux Kernel (multiple), OpenSSL (WID-SEC-2026-1852), Microsoft Developer Tools (WID-SEC-2026-1845), Netty, WebKitGTK, Rsync, and HTTP/2 implementations were refreshed; apply vendor patches per prior guidance.
ACTIVE THREATS AND CAMPAIGNS
NEW — DragonForce Ransomware: Microsoft Teams C2 Concealment via Backdoor.Turn Symantec and Carbon Black have reported that DragonForce ransomware affiliates deployed a custom Go-based RAT named Backdoor.Turn that tunnels C2 traffic through Microsoft Teams relay infrastructure. The technique abuses legitimate Teams relay endpoints to blend malicious traffic with normal collaboration traffic, complicating network-based detection. The backdoor was deployed against a major U.S. services firm. Organizations should review Teams relay traffic for anomalous patterns and ensure endpoint detection covers Go-based implants.
NEW — Gentlemen Ransomware: Active EDR Killer Suite Development The Gentlemen RaaS operation is actively developing and maintaining multiple EDR killer tools to assist affiliates in disabling endpoint defenses prior to ransomware deployment. This represents a deliberate investment in defense evasion capability. Security teams should verify EDR tamper protection is enabled and monitor for driver-based or process-injection-based EDR termination attempts.
STATUS CHANGE — FortiBleed: CISA Alert and NCSC Advisory Issued CISA and the UK NCSC have both issued formal advisories on the FortiBleed credential leak, now confirmed at approximately 74,000 Fortinet devices. CISA urges immediate hardening of all internet-accessible Fortinet devices. Credential rotation and MFA enforcement remain the primary mitigations. Full details reported yesterday.
NEW — SocGholish / Evil Corp Takedown: Operation Endgame Phase International law enforcement cleaned nearly 15,000 SocGholish-infected WordPress sites and took down over 100 servers linked to the SocGholish botnet and Evil Corp. Organizations should scan WordPress deployments for residual SocGholish injections and review web proxy logs for traffic to known SocGholish domains.
ONGOING — Dropping Elephant memory-resident RAT campaign: IOCs and full details reported 2026-06-18; block domains chinagreenenergy[.]org and gcl-power[.]org; hunt for GoogleErrorReport scheduled task. ONGOING — INC Ransomware RaaS: 830+ victims since 2023; expanding following LockBit and BlackCat disruptions; review ransomware resilience posture. ONGOING — Icarus / Klue OAuth breach: Salesforce CRM data theft via OAuth token abuse; review OAuth application grants and Salesforce access logs.
SECURITY NEWS AND CONTEXT
NGINX Critical Patches: F5 issued out-of-band patches for two critical NGINX flaws on 2026-06-18, including a use-after-free in the HTTP/3 module; covered in Critical Vulnerabilities.
ShapedPlugin Supply Chain Attack: Multiple WordPress plugins from ShapedPlugin were compromised via the vendor’s official update system, distributing malicious releases to paying customers. Organizations using ShapedPlugin products should audit installed plugin versions and review for indicators of compromise.
NCSC AI Coding Guidance: UK NCSC published guidance on calibrating security oversight for AI-assisted software development, recommending risk-proportionate review based on code sensitivity and deployment context.
RECOMMENDED ACTIONS
- Patch Splunk Enterprise (CVE-2026-20253) immediately — CISA KEV deadline is 2026-06-21; restrict PostgreSQL sidecar service network access.
- Apply F5 out-of-band patches for NGINX CVE-2026-42530 and related flaws; disable HTTP/3 module if not required.
- Upgrade pgAdmin 4 to version 9.16 to address CVE-2026-12044 through CVE-2026-12048; restrict pgAdmin to trusted networks.
- Apply Microsoft patches for CVE-2026-54130 (M365 Copilot) and CVE-2026-47647 (Dynamics 365) when released; monitor MSRC.
- Apply Drupal Core security updates per BSI WID-SEC-2026-2002; review for signs of compromise.
- Apply Cisco ISE patches per BSI WID-SEC-2026-1989; review ISE administrator activity.
- Rotate all Fortinet VPN credentials and enforce MFA — CISA and NCSC have now formally confirmed the FortiBleed threat.
- Scan WordPress deployments for SocGholish injections following Operation Endgame takedown; review proxy logs for SocGholish domains.
- Enable EDR tamper protection and monitor for driver-based EDR termination attempts in response to Gentlemen ransomware EDR killer activity.
- Continue remediation of previously reported items: CVE-2026-20262 (Cisco SD-WAN, KEV deadline 2026-06-29), CVE-2026-42271 (LiteLLM, KEV deadline 2026-06-22), CVE-2026-50656 (Defender RoguePlanet, no patch), CVE-2026-0257 (PAN-OS), CVE-2026-5027 (Langflow), CVE-2026-50751 (Check Point).