Daily briefing · June 27, 2026

Ten KEV-Confirmed Vulnerabilities Dominate the Spotlight: Joomla, PeopleSoft, Splunk, and More Under Active Exploitation

Automated Vexday summary · sources: NVD, CISA KEV, EPSS

June 27, 2026 recorded no new CVE publications, but the threat landscape remains sharp: all ten vulnerabilities highlighted today carry confirmed active exploitation status (KEV), spanning web CMS plugins, enterprise ERP platforms, SIEM infrastructure, VPN gateways, browsers, and network controllers. The combination of unauthenticated attack vectors, public proof-of-concept code, and high EPSS scores across the board makes this a high-urgency patch cycle for defenders. Organizations still running unpatched instances of any affected product face immediate, realistic risk of compromise.

Today’s brief
  • All 10 featured CVEs are under active exploitation (KEV-confirmed) with public PoC code available — patching is not optional.
  • Two vulnerabilities (Joomla JCE and Oracle PeopleSoft) carry CVSS 10.0 and 9.8 respectively, allowing full unauthenticated remote takeover.
  • Splunk Enterprise and Quantum Security Gateway flaws enable unauthenticated file manipulation and VPN authentication bypass at scale.
  • Network infrastructure (Cisco SD-WAN, Arista EOS, SolarWinds Serv-U) is also in the crosshairs, extending risk beyond traditional application layers.
Critical highlights
1
CVE-2026-48907KEVCVSS 10PoCaffects Joomla Content Editor (JCE) extension for Joomla
A critical CVSS 10.0 flaw in the JCE editor extension for Joomla lets completely unauthenticated attackers create editor profiles and upload arbitrary PHP code for server-side execution — full remote code execution with zero credentials required on any exposed Joomla site running JCE.
2
CVE-2026-35273KEVCVSS 9.8PoCaffects PeopleSoft Enterprise PeopleTools
Oracle PeopleSoft (PeopleTools 8.61/8.62) exposes a CVSS 9.8 unauthenticated network-accessible endpoint that allows complete system takeover via HTTP; with 90% EPSS and a public PoC, automated exploitation at scale is a near-certainty for unpatched deployments.
3
CVE-2026-20253KEVCVSS 9.8PoCaffects Splunk Enterprise
Splunk Enterprise versions below 10.2.4 and 10.0.7 expose a PostgreSQL sidecar service endpoint with no authentication, letting any network-reachable attacker create or truncate arbitrary files — a direct path to data destruction or code execution on the Splunk host.
4
CVE-2026-50751KEVCVSS 9.3PoCaffects Quantum Security Gateway
A logic flaw in deprecated IKEv1 certificate validation on Quantum Security Gateways allows unauthenticated remote attackers to fully bypass user authentication and establish VPN connections without valid credentials — effectively granting attackers the same access level as legitimate remote users.
5
CVE-2026-11645KEVHIGH 8.8PoCaffects Chrome
An out-of-bounds read/write in Chrome's V8 JavaScript engine (versions before 149.0.7827.103) can be triggered by a crafted HTML page, achieving arbitrary code execution inside the browser sandbox — a browser-delivered exploit requiring only that a user visits a malicious or compromised site.
6
CVE-2026-54420KEVHIGH 8.5PoCaffects cPanel Plugin
The LiteSpeed cPanel plugin before 2.4.8 mishandles symlinks on shared hosting servers, allowing any user with FTP or web shell access to escape CloudLinux/CageFS containment and impact other tenants on the same host — a critical shared-hosting isolation failure actively exploited since May 2026.
7
CVE-2025-48595KEVHIGH 8.4PoCaffects Android
An integer overflow in Android's core platform enables local privilege escalation to higher execution levels without any additional permissions or user interaction — making it a reliable post-access escalation tool for malware or malicious apps already running on a device.
8
CVE-2026-20245KEVHIGH 7.8PoCaffects Cisco Catalyst SD-WAN Controller
Authenticated local attackers on Cisco Catalyst SD-WAN Controller, Manager, or Validator can escalate to root by supplying a crafted file to the CLI — in SD-WAN environments where multiple administrators share access, this flaw breaks the principle of least privilege and enables full infrastructure control.
9
CVE-2026-28318KEVHIGH 7.5PoCaffects Serv-U
SolarWinds Serv-U crashes when it receives specially crafted unauthenticated POST requests using Content-Encoding: deflate — a trivially reproducible denial-of-service that requires no credentials and can be weaponized to disrupt managed file transfer operations continuously.
10
CVE-2026-7473KEVMEDIUM 6.9PoCaffects EOS
Arista EOS platforms with VXLAN, decap-group, or GRE tunnel configurations will incorrectly decapsulate and forward unexpected tunneled packets to any destination IP matching a configured decap address, enabling traffic injection and potential network segmentation bypass without authentication.
Today’s recommendation: Prioritize immediate patching of CVE-2026-48907, CVE-2026-35273, and CVE-2026-20253 given their unauthenticated attack vectors, CVSS scores at or above 9.8, and confirmed in-the-wild exploitation; for assets that cannot be patched immediately, apply network-level controls to restrict access to affected services and monitor for anomalous file creation, authentication, and tunnel traffic patterns.
With ten actively exploited vulnerabilities spanning web applications, enterprise platforms, network controllers, and end-user browsers, now is the right moment to validate which of these products exist in your environment and whether your current controls would detect or block exploitation attempts before an attacker does.New vulnerabilities surface every day — does your defense keep up? Get a free initial review of your attack surface.Meet the Autonomous AI Pentest Agent →
Previous briefings
August 6, 202610 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 202632 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →