Daily briefing · June 27, 2026
Ten KEV-Confirmed Vulnerabilities Dominate the Spotlight: Joomla, PeopleSoft, Splunk, and More Under Active Exploitation
June 27, 2026 recorded no new CVE publications, but the threat landscape remains sharp: all ten vulnerabilities highlighted today carry confirmed active exploitation status (KEV), spanning web CMS plugins, enterprise ERP platforms, SIEM infrastructure, VPN gateways, browsers, and network controllers. The combination of unauthenticated attack vectors, public proof-of-concept code, and high EPSS scores across the board makes this a high-urgency patch cycle for defenders. Organizations still running unpatched instances of any affected product face immediate, realistic risk of compromise.
Today’s brief
- All 10 featured CVEs are under active exploitation (KEV-confirmed) with public PoC code available — patching is not optional.
- Two vulnerabilities (Joomla JCE and Oracle PeopleSoft) carry CVSS 10.0 and 9.8 respectively, allowing full unauthenticated remote takeover.
- Splunk Enterprise and Quantum Security Gateway flaws enable unauthenticated file manipulation and VPN authentication bypass at scale.
- Network infrastructure (Cisco SD-WAN, Arista EOS, SolarWinds Serv-U) is also in the crosshairs, extending risk beyond traditional application layers.
Critical highlights
1
A critical CVSS 10.0 flaw in the JCE editor extension for Joomla lets completely unauthenticated attackers create editor profiles and upload arbitrary PHP code for server-side execution — full remote code execution with zero credentials required on any exposed Joomla site running JCE.
2
Oracle PeopleSoft (PeopleTools 8.61/8.62) exposes a CVSS 9.8 unauthenticated network-accessible endpoint that allows complete system takeover via HTTP; with 90% EPSS and a public PoC, automated exploitation at scale is a near-certainty for unpatched deployments.
3
Splunk Enterprise versions below 10.2.4 and 10.0.7 expose a PostgreSQL sidecar service endpoint with no authentication, letting any network-reachable attacker create or truncate arbitrary files — a direct path to data destruction or code execution on the Splunk host.
4
A logic flaw in deprecated IKEv1 certificate validation on Quantum Security Gateways allows unauthenticated remote attackers to fully bypass user authentication and establish VPN connections without valid credentials — effectively granting attackers the same access level as legitimate remote users.
5
An out-of-bounds read/write in Chrome's V8 JavaScript engine (versions before 149.0.7827.103) can be triggered by a crafted HTML page, achieving arbitrary code execution inside the browser sandbox — a browser-delivered exploit requiring only that a user visits a malicious or compromised site.
6
The LiteSpeed cPanel plugin before 2.4.8 mishandles symlinks on shared hosting servers, allowing any user with FTP or web shell access to escape CloudLinux/CageFS containment and impact other tenants on the same host — a critical shared-hosting isolation failure actively exploited since May 2026.
7
An integer overflow in Android's core platform enables local privilege escalation to higher execution levels without any additional permissions or user interaction — making it a reliable post-access escalation tool for malware or malicious apps already running on a device.
8
Authenticated local attackers on Cisco Catalyst SD-WAN Controller, Manager, or Validator can escalate to root by supplying a crafted file to the CLI — in SD-WAN environments where multiple administrators share access, this flaw breaks the principle of least privilege and enables full infrastructure control.
9
SolarWinds Serv-U crashes when it receives specially crafted unauthenticated POST requests using Content-Encoding: deflate — a trivially reproducible denial-of-service that requires no credentials and can be weaponized to disrupt managed file transfer operations continuously.
10
Arista EOS platforms with VXLAN, decap-group, or GRE tunnel configurations will incorrectly decapsulate and forward unexpected tunneled packets to any destination IP matching a configured decap address, enabling traffic injection and potential network segmentation bypass without authentication.
Today’s recommendation: Prioritize immediate patching of CVE-2026-48907, CVE-2026-35273, and CVE-2026-20253 given their unauthenticated attack vectors, CVSS scores at or above 9.8, and confirmed in-the-wild exploitation; for assets that cannot be patched immediately, apply network-level controls to restrict access to affected services and monitor for anomalous file creation, authentication, and tunnel traffic patterns.
With ten actively exploited vulnerabilities spanning web applications, enterprise platforms, network controllers, and end-user browsers, now is the right moment to validate which of these products exist in your environment and whether your current controls would detect or block exploitation attempts before an attacker does.New vulnerabilities surface every day — does your defense keep up? Get a free initial review of your attack surface.Meet the Autonomous AI Pentest Agent →Previous briefings
August 6, 2026 — 10 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026 — Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026 — Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026 — Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026 — Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026 — WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026 — Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 2026 — 32 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026 — Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026 — Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026 — CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026 — Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026 — CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026 — Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →