IBM Langflow OSS · MISP · Multiple TP-Link models including Archer MR200 v7/v8
DAILY THREAT INTELLIGENCE BRIEFING Date: 2026-06-23 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership
EXECUTIVE SUMMARY
The most significant new developments today are a large-scale supply chain attack backdooring multiple ShapedPlugin WordPress Pro plugins, a new OXLOADER/CastleStealer malvertising campaign attributed to a financially motivated Russian-speaking actor, and the FortiBleed campaign’s confirmed use of custom credential-harvesting sniffers on compromised FortiGate devices. The BSI has published a strategic advisory on AI-accelerated cyber threats, aligned with a parallel Five Eyes warning. Multiple critical vulnerabilities in IBM Langflow OSS and MISP also require attention.
CRITICAL VULNERABILITIES
NEW
CVE-2026-10561 / CVE-2026-7664 (IBM Langflow OSS)
- Affected products: IBM Langflow OSS 1.0.0 through 1.9.3 (CVE-2026-10561); 1.0.0 through 1.8.4 (CVE-2026-7664)
- Severity: CVSS 10.0 / CVSS 9.8
- EPSS: 0 (newly published; no exploitation data yet)
- Technical detail: CVE-2026-10561 combines improper isolation of Python execution with an authentication bypass, allowing an unauthenticated remote attacker to execute arbitrary code with service-level privileges. CVE-2026-7664 is a separate authorization enforcement failure in the Streaming endpoint that permits unauthenticated access to protected MCP project resources and operations. Both flaws are independently exploitable without credentials, making any internet-exposed Langflow instance fully compromised by a remote attacker. IBM Langflow OSS is increasingly deployed in enterprise AI workflow and automation pipelines.
- Exploitation status: No confirmed in-the-wild exploitation. The unauthenticated RCE class and CVSS 10.0 rating make this an immediate patching priority.
- Remediation: Upgrade IBM Langflow OSS to 1.9.4 or later (CVE-2026-10561) and 1.8.5 or later (CVE-2026-7664). Immediately isolate any internet-exposed Langflow instances. Review access logs for unexpected API calls or MCP resource access. BSI advisory WID-SEC-2026-2030 covers these flaws.
CVE-2026-56422 / CVE-2026-56447 / CVE-2026-56446 (MISP)
- Affected products: MISP versions 0 through 2.5.41
- Severity: CVSS 9.4 / CVSS 9.3 / CVSS 8.7
- EPSS: 0 (newly published)
- Technical detail: Three distinct flaws affect MISP, the widely used open-source threat intelligence platform. CVE-2026-56422 allows mass assignment attacks via client-controlled request fields including primary keys and ownership foreign keys across multiple controllers, enabling privilege escalation and data manipulation. CVE-2026-56447 allows a site administrator to point the Kafka rdkafka configuration at an arbitrary filesystem path, enabling local file read via INI parsing. CVE-2026-56446 allows log path manipulation with attacker-controlled content, enabling log injection or potential path traversal. These flaws are particularly significant given MISP’s role in European threat intelligence sharing communities, including CIRCL-operated instances.
- Exploitation status: No confirmed in-the-wild exploitation. Exploitation of CVE-2026-56422 requires authentication; the other two require site administrator access.
- Remediation: Upgrade MISP to version 2.5.42 or later. Restrict site administrator access to trusted personnel. Review MISP configuration for unexpected Kafka or log path settings. Advisories published by CIRCL.
CVE-2026-11834 (TP-Link Routers — DHCP Command Injection)
- Affected products: Multiple TP-Link models including Archer MR200 v7/v8, Archer C20 V5/V6, Archer VR2100 v1, TL-MR6400 v7, Archer MR402 v1
- Severity: CVSS 8.7
- EPSS: 0 (newly published)
- Technical detail: Insufficient validation of externally supplied DHCP option data in the DHCP option processing logic allows a network-adjacent attacker to inject and execute arbitrary commands on affected routers. Exploitation requires the attacker to be positioned to supply malicious DHCP responses, achievable via a rogue DHCP server on the same network segment or through a compromised upstream device. These consumer and SMB-grade routers are widely deployed in European home office and small business environments.
- Exploitation status: No confirmed in-the-wild exploitation.
- Remediation: Apply firmware updates per TP-Link’s advisory (build dates range from 250605 to 260608 depending on model). Segment router management interfaces from untrusted networks. Disable DHCP client on WAN interfaces where static addressing is feasible.
CVE-2026-12249 (Canonical ADSys — Ubuntu AD Certificate Auto-Enrollment)
- Affected products: Ubuntu 24.04 LTS (fix: 0.16.3~24.04.2ubuntu0.24.04.1), Ubuntu 22.04 LTS (fix: 0.16.3~22.04.2ubuntu0.22.04.1)
- Severity: CVSS 9.0
- EPSS: 0 (newly published)
- Technical detail: During Active Directory Certificate Services auto-enrollment via the vendored Samba client script, ADSys does not adequately validate the certificate enrollment process, potentially allowing a man-in-the-middle attacker to intercept or manipulate certificate issuance. This affects Ubuntu enterprise deployments integrated with Microsoft AD CS, a common configuration in hybrid Linux/Windows enterprise environments. European organizations running Ubuntu in AD-joined configurations should treat this as a priority.
- Exploitation status: No confirmed in-the-wild exploitation.
- Remediation: Apply the patched ADSys package via standard Ubuntu security updates on both 22.04 and 24.04 LTS systems. Verify AD CS enrollment integrity after patching.
ONGOING
- CVE-2026-42271 (LiteLLM): CISA KEV deadline was 2026-06-22 — verify patch completion; BSI WID-SEC-2026-1288 updated.
- CVE-2026-56382 (Craft CMS): authenticated RCE; upgrade to 5.9.14 or later.
- CVE-2026-56265 / CVE-2026-56266 (Crawl4AI): hardcoded JWT key and SSRF; upgrade to 0.8.7 and rotate keys.
- CVE-2026-20262 (Cisco Catalyst SD-WAN Manager): actively exploited; CISA KEV deadline 2026-06-29; patch immediately.
- CVE-2026-4020 (Gravity SMTP WordPress): actively exploited; update plugin and rotate credentials.
- CVE-2026-0257 (Palo Alto PAN-OS GlobalProtect): actively exploited; apply PAN-OS patches.
- CVE-2026-5027 (Langflow): actively exploited; isolate from internet.
- CVE-2026-50751 (Check Point Security Gateway): actively exploited; apply hotfix sk185033.
EUROPEAN ADVISORIES
BSI published several new and updated advisories on 2026-06-22. New advisories of note:
WID-SEC-2026-2030 (Langflow): covered in Critical Vulnerabilities above.
WID-SEC-2026-2020 (Microsoft 365 Copilot) and WID-SEC-2026-2017 (Microsoft Azure AI Bot Service, Azure Active Directory, Azure Synapse): BSI rates these high severity. Flaws enable privilege escalation, command injection, data manipulation, and information disclosure by remote unauthenticated or authenticated attackers. Organizations using Microsoft 365 Copilot or the affected Azure services should apply available Microsoft mitigations and review access controls.
WID-SEC-2026-2022 (Microsoft Exchange Online): A remotely exploitable privilege escalation flaw affecting Exchange Online. Authenticated attackers can elevate privileges. Apply Microsoft’s remediation guidance promptly.
WID-SEC-2026-2027 (Gitea): Multiple flaws enabling privilege escalation, user impersonation, security bypass, data manipulation, and information disclosure. Organizations running self-hosted Gitea instances — common in European DevOps environments — should update to the latest release immediately.
WID-SEC-2026-2029 (Apache NiFi): Multiple flaws including SQL injection, file manipulation, and security bypass. Apply the latest Apache NiFi update; restrict NiFi web UI to trusted networks.
BSI also published a strategic IT-Sicherheitsinformation (BITS) on AI-driven cyber threats — see Security News section.
Updated advisories (no new detail beyond prior coverage): WID-SEC-2026-1288 (LiteLLM), WID-SEC-2026-1766 (WebKitGTK), WID-SEC-2026-1700/1802/1827/1870 (Linux Kernel), WID-SEC-2026-1641 (Evince), WID-SEC-2026-1845 (Microsoft Developer Tools), WID-SEC-2026-1828 (VMware Tanzu Spring Framework), WID-SEC-2026-1716 (Rancher), WID-SEC-2026-1681 (7-Zip), WID-SEC-2026-1544 (PostgreSQL).
ACTIVE THREATS AND CAMPAIGNS
NEW — ShapedPlugin WordPress Supply Chain Attack Unknown threat actors compromised the build and distribution pipeline of ShapedPlugin, a WordPress plugin vendor, injecting backdoor code into Pro plugin releases distributed through official licensed update channels. Multiple plugins are affected. Any WordPress site running ShapedPlugin Pro plugins should be treated as potentially compromised. Immediately audit installed plugin versions, check for unauthorized admin accounts or webshells, and apply clean plugin updates once available. Wordfence has published analysis.
NEW — OXLOADER / CastleStealer Malvertising Campaign Elastic Security Labs has identified a new campaign using malicious Google Ads to distribute a previously undocumented loader, OXLOADER, which delivers the CastleStealer credential-stealing malware. The threat actor is assessed as likely Russian-speaking and financially motivated. Organizations should enforce ad-blocking at the network perimeter, brief users on malvertising risks, and monitor endpoint telemetry for OXLOADER indicators.
STATUS CHANGE — FortiBleed Campaign SOCRadar has confirmed that the FortiBleed campaign used custom-built sniffers deployed on compromised FortiGate devices to harvest authentication secrets and credentials directly from firewall memory. This materially elevates the credential theft risk for all organizations with previously compromised FortiGate devices. Rotate all credentials that may have transited affected devices, not just VPN credentials. Enforce MFA on all accounts.
NEW — Squidbleed (Squid Proxy Heap Over-Read) A 29-year-old heap over-read bug in Squid proxy, dubbed Squidbleed, can leak another user’s cleartext HTTP request including credentials and session tokens to any user permitted to send traffic through the same proxy. The flaw traces to a 1997 FTP-parsing change and is present in Squid’s default configuration. Organizations running shared Squid proxy deployments should apply available patches and review proxy access controls.
ONGOING — AryStinger Botnet: 4,300+ legacy routers compromised as proxy network; audit D-Link firmware and replace EOL devices. ONGOING — Sapphire Sleet npm supply chain: audit npm dependencies for Mastra AI packages. ONGOING — Gentlemen RaaS / GentleKiller: EDR killer in active distribution; verify tamper protection.
SECURITY NEWS AND CONTEXT
BSI and Five Eyes AI threat warning: The BSI published a strategic advisory warning that current AI models can autonomously identify vulnerabilities and generate exploit code at scale, structurally lowering attacker barriers while defenders remain constrained by operational processes. The UK NCSC and Five Eyes partners published a parallel leadership-focused advisory the same day. Security leadership should review both documents and assess AI-accelerated patch response capabilities.
Unit 42 cloud bucket hijacking research: Unit 42 has detailed a technique exploiting global namespace uniqueness in cloud storage to redirect data streams across major cloud providers. Organizations using cloud storage pipelines should audit bucket naming conventions and access policies for hijacking exposure.
WhatsApp phishing campaign: An active campaign is targeting WhatsApp users across multiple countries with fake business documents that deliver VBScript payloads enabling remote system access. Brief users and block VBScript execution via application control policies.
RECOMMENDED ACTIONS
- Upgrade IBM Langflow OSS immediately: to 1.9.4+ (CVE-2026-10561) and 1.8.5+ (CVE-2026-7664); isolate any internet-exposed instances now.
- Upgrade MISP to 2.5.42 or later; audit site administrator access and review Kafka and log path configurations (CVE-2026-56422/56447/56446).
- Audit all WordPress sites running ShapedPlugin Pro plugins for backdoors, unauthorized admin accounts, and webshells; apply clean updates.
- Rotate all credentials on systems that may have been exposed via FortiBleed-compromised FortiGate devices; enforce MFA on all accounts.
- Apply TP-Link firmware updates for affected Archer and TL-MR6400 models (CVE-2026-11834); segment router management interfaces.
- Apply ADSys patches on Ubuntu 22.04 and 24.04 LTS systems joined to Active Directory with AD CS enrollment (CVE-2026-12249).
- Apply Gitea and Apache NiFi updates per BSI WID-SEC-2026-2027 and WID-SEC-2026-2029; restrict NiFi UI to trusted networks.
- Patch Squid proxy deployments to remediate Squidbleed; review shared proxy access controls.
- Block VBScript execution via application control policies; brief users on WhatsApp malvertising and fake document lures.
- Continue remediation of previously reported items: CVE-2026-20262 (Cisco SD-WAN, KEV deadline 2026-06-29), CVE-2026-42271 (LiteLLM, KEV deadline passed), CVE-2026-56382 (Craft CMS), CVE-2026-0257 (PAN-OS), CVE-2026-5027 (Langflow), CVE-2026-50751 (Check Point), CVE-2026-4020 (Gravity SMTP).