Daily briefing · June 26, 2026
10 Actively Exploited CVEs Dominate: Joomla RCE, Splunk File Write, and PeopleSoft Takeover Lead Critical Wave
Although June 26, 2026 registered no new CVE publications, defenders face a dense landscape of actively exploited vulnerabilities spanning enterprise platforms, network infrastructure, and end-user software. All ten highlighted entries carry KEV status, meaning real-world exploitation has been confirmed, demanding immediate prioritization. The breadth of affected products — from CMS extensions and SIEM platforms to SD-WAN controllers and mobile operating systems — underscores how heterogeneous the current threat surface truly is.
Today’s brief
- All 10 featured CVEs are confirmed under active exploitation (KEV), with public PoCs available for every one of them.
- Three vulnerabilities score CVSS 9.8 or higher: unauthenticated RCE or full system takeover is achievable without credentials in Joomla JCE, Splunk Enterprise, and Oracle PeopleSoft.
- VPN authentication bypass in Quantum Security Gateway and a Chrome V8 out-of-bounds RCE add browser and remote-access risk to the mix.
- Cisco SD-WAN, SolarWinds Serv-U, Android, LiteSpeed cPanel plugin, and Arista EOS round out a wide-ranging set of critical patching obligations.
Critical highlights
1
An unauthenticated attacker can create new editor profiles in the JCE extension for Joomla and leverage that to upload and execute arbitrary PHP code on the web server — effectively a zero-click remote code execution path for any publicly reachable Joomla site running JCE.
2
Splunk Enterprise exposes a PostgreSQL sidecar service endpoint with no authentication, letting any network-reachable user create or truncate arbitrary files; in practice this can be chained to overwrite configuration or executable files and achieve code execution on the Splunk server.
3
This unauthenticated, network-accessible flaw in Oracle PeopleSoft PeopleTools (versions 8.61 and 8.62) can result in complete takeover of the PeopleSoft instance, putting HR, financial, and ERP data at direct risk with no credentials required.
4
A logic flaw in deprecated IKEv1 certificate validation in Quantum Security Gateway allows an unauthenticated remote attacker to bypass VPN authentication entirely, establishing a full remote access session without a valid password — a critical exposure for organizations relying on this gateway for perimeter control.
5
An out-of-bounds read and write in Chrome's V8 JavaScript engine enables arbitrary code execution inside the browser sandbox via a malicious web page, affecting all Chrome versions prior to 149.0.7827.103 and exposing any user who browses to attacker-controlled content.
6
The LiteSpeed cPanel plugin mishandles symlinks supplied by users with FTP or web shell access on shared hosting servers running CloudLinux/CageFS, allowing privilege escalation beyond CageFS boundaries — a significant risk for hosting providers with untrusted tenants.
7
An integer overflow in multiple Android system locations allows local privilege escalation to higher execution contexts with no additional privileges or user interaction required, making it a practical tool for malicious apps or post-exploitation persistence on unpatched Android devices.
8
An authenticated local attacker on Cisco Catalyst SD-WAN Controller, Manager, or Validator can supply a crafted file to the CLI and execute arbitrary commands as root, converting any compromised local account into full infrastructure control over SD-WAN fabric components.
9
SolarWinds Serv-U crashes when it receives a specially crafted unauthenticated POST request using Content-Encoding: deflate, creating a reliable denial-of-service vector against file transfer infrastructure without requiring any credentials.
10
Affected Arista EOS switches with VXLAN, decap-group, or GRE tunnel configurations will incorrectly decapsulate and forward unexpected tunneled packets destined for the device's decapsulation IP, potentially enabling traffic injection or network segmentation bypass by an attacker who can reach the switch.
Today’s recommendation: Organizations should immediately verify patch status for all ten CVEs against their asset inventory, prioritizing CVE-2026-48907, CVE-2026-20253, and CVE-2026-35273 given their CVSS 9.8–10.0 scores and confirmed active exploitation; where patching cannot be applied instantly, network-level controls such as blocking unauthenticated access to exposed service endpoints and disabling deprecated IKEv1 should be enforced as interim mitigations.
With confirmed exploitation confirmed across this many product families simultaneously, the most pressing question for any security team is whether their own asset inventory accurately reflects which of these systems are internet-exposed — validating that surface from the outside in is the fastest way to prioritize what needs attention first.Knowing the flaw exists is half the job; the other half is knowing if it affects you. Start with a no-cost exposure test.Meet the Autonomous AI Pentest Agent →Previous briefings
August 6, 2026 — 10 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026 — Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026 — Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026 — Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026 — Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026 — WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026 — Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 2026 — 32 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026 — Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026 — Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026 — CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026 — Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026 — CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026 — Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →