Daily briefing · June 26, 2026

10 Actively Exploited CVEs Dominate: Joomla RCE, Splunk File Write, and PeopleSoft Takeover Lead Critical Wave

Automated Vexday summary · sources: NVD, CISA KEV, EPSS

Although June 26, 2026 registered no new CVE publications, defenders face a dense landscape of actively exploited vulnerabilities spanning enterprise platforms, network infrastructure, and end-user software. All ten highlighted entries carry KEV status, meaning real-world exploitation has been confirmed, demanding immediate prioritization. The breadth of affected products — from CMS extensions and SIEM platforms to SD-WAN controllers and mobile operating systems — underscores how heterogeneous the current threat surface truly is.

Today’s brief
  • All 10 featured CVEs are confirmed under active exploitation (KEV), with public PoCs available for every one of them.
  • Three vulnerabilities score CVSS 9.8 or higher: unauthenticated RCE or full system takeover is achievable without credentials in Joomla JCE, Splunk Enterprise, and Oracle PeopleSoft.
  • VPN authentication bypass in Quantum Security Gateway and a Chrome V8 out-of-bounds RCE add browser and remote-access risk to the mix.
  • Cisco SD-WAN, SolarWinds Serv-U, Android, LiteSpeed cPanel plugin, and Arista EOS round out a wide-ranging set of critical patching obligations.
Critical highlights
1
CVE-2026-48907KEVCVSS 10PoCaffects Joomla Content Editor (JCE) extension for Joomla
An unauthenticated attacker can create new editor profiles in the JCE extension for Joomla and leverage that to upload and execute arbitrary PHP code on the web server — effectively a zero-click remote code execution path for any publicly reachable Joomla site running JCE.
2
CVE-2026-20253KEVCVSS 9.8PoCaffects Splunk Enterprise
Splunk Enterprise exposes a PostgreSQL sidecar service endpoint with no authentication, letting any network-reachable user create or truncate arbitrary files; in practice this can be chained to overwrite configuration or executable files and achieve code execution on the Splunk server.
3
CVE-2026-35273KEVCVSS 9.8PoCaffects PeopleSoft Enterprise PeopleTools
This unauthenticated, network-accessible flaw in Oracle PeopleSoft PeopleTools (versions 8.61 and 8.62) can result in complete takeover of the PeopleSoft instance, putting HR, financial, and ERP data at direct risk with no credentials required.
4
CVE-2026-50751KEVCVSS 9.3PoCaffects Quantum Security Gateway
A logic flaw in deprecated IKEv1 certificate validation in Quantum Security Gateway allows an unauthenticated remote attacker to bypass VPN authentication entirely, establishing a full remote access session without a valid password — a critical exposure for organizations relying on this gateway for perimeter control.
5
CVE-2026-11645KEVHIGH 8.8PoCaffects Chrome
An out-of-bounds read and write in Chrome's V8 JavaScript engine enables arbitrary code execution inside the browser sandbox via a malicious web page, affecting all Chrome versions prior to 149.0.7827.103 and exposing any user who browses to attacker-controlled content.
6
CVE-2026-54420KEVHIGH 8.5PoCaffects cPanel Plugin
The LiteSpeed cPanel plugin mishandles symlinks supplied by users with FTP or web shell access on shared hosting servers running CloudLinux/CageFS, allowing privilege escalation beyond CageFS boundaries — a significant risk for hosting providers with untrusted tenants.
7
CVE-2025-48595KEVHIGH 8.4PoCaffects Android
An integer overflow in multiple Android system locations allows local privilege escalation to higher execution contexts with no additional privileges or user interaction required, making it a practical tool for malicious apps or post-exploitation persistence on unpatched Android devices.
8
CVE-2026-20245KEVHIGH 7.8PoCaffects Cisco Catalyst SD-WAN Controller
An authenticated local attacker on Cisco Catalyst SD-WAN Controller, Manager, or Validator can supply a crafted file to the CLI and execute arbitrary commands as root, converting any compromised local account into full infrastructure control over SD-WAN fabric components.
9
CVE-2026-28318KEVHIGH 7.5PoCaffects Serv-U
SolarWinds Serv-U crashes when it receives a specially crafted unauthenticated POST request using Content-Encoding: deflate, creating a reliable denial-of-service vector against file transfer infrastructure without requiring any credentials.
10
CVE-2026-7473KEVMEDIUM 6.9PoCaffects EOS
Affected Arista EOS switches with VXLAN, decap-group, or GRE tunnel configurations will incorrectly decapsulate and forward unexpected tunneled packets destined for the device's decapsulation IP, potentially enabling traffic injection or network segmentation bypass by an attacker who can reach the switch.
Today’s recommendation: Organizations should immediately verify patch status for all ten CVEs against their asset inventory, prioritizing CVE-2026-48907, CVE-2026-20253, and CVE-2026-35273 given their CVSS 9.8–10.0 scores and confirmed active exploitation; where patching cannot be applied instantly, network-level controls such as blocking unauthenticated access to exposed service endpoints and disabling deprecated IKEv1 should be enforced as interim mitigations.
With confirmed exploitation confirmed across this many product families simultaneously, the most pressing question for any security team is whether their own asset inventory accurately reflects which of these systems are internet-exposed — validating that surface from the outside in is the fastest way to prioritize what needs attention first.Knowing the flaw exists is half the job; the other half is knowing if it affects you. Start with a no-cost exposure test.Meet the Autonomous AI Pentest Agent →
Previous briefings
August 6, 202610 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 202632 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →