Daily briefing · June 29, 2026
Unauthenticated RCE in Joomla Extension Leads Monday's Batch of Six Critical CVEs
June 29, 2026 brought 220 new vulnerabilities, six of them rated Critical, with no confirmed active exploitation yet — but several flaws are severe enough to demand immediate attention. A perfect-score CVSS 10.0 unauthenticated file-upload-to-RCE in a Joomla extension tops the list, joined by privilege escalation in Rancher, multiple critical issues in Coolify, and web-content memory corruption bugs in Apple's Safari, iOS, and iPadOS. With a public proof-of-concept already circulating for the Gorse authentication bypass, the window for safe remediation is narrowing fast.
Today’s brief
- CVE-2026-56290 scores a perfect CVSS 10.0: unauthenticated file upload leads to full RCE on any Joomla site running Page Builder CK.
- Coolify racks up three separate critical/high vulnerabilities (CVE-2026-57498, CVE-2026-34594, CVE-2026-34597) covering authorization bypass, command injection, and RCE — update immediately.
- Gorse's authentication bypass (CVE-2026-56782) already has a public PoC, exposing all user data on default-configured instances with no admin key set.
- Apple issued Safari/iOS/iPadOS 26.5.2 fixes for two memory corruption bugs (CVE-2026-43731, CVE-2026-43705) triggerable by visiting a malicious webpage.
6
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
Any unauthenticated attacker can upload an executable file through the Page Builder CK extension for Joomla and achieve full remote code execution on the host — a maximum-severity risk that requires no credentials whatsoever. Sites running this extension should treat it as actively compromised until patched or disabled.
2
Arbitrary file deletion affecting Paid Videochat Turnkey Site versions up to 7.4.8 can allow an attacker to destroy critical files, potentially destabilizing or taking down the platform entirely. Operators of this software should update or restrict access immediately.
3
Coolify's Livewire UI components accept server_id and destination_uuid from URL query parameters without validating team ownership, allowing authenticated users to access or manipulate servers belonging to other teams. This breaks multi-tenant isolation in self-hosted deployments and should be patched to version 4.0.0-beta.474 or later.
4
Users holding the Project Owner role in Rancher can abuse improper privilege handling to escalate to higher-level permissions across affected versions 2.12, 2.13, and 2.14. Organizations relying on Rancher's RBAC model for workload separation must apply the respective patch releases without delay.
5
A path traversal flaw in the HTTP tool URL builder of MCP Toolbox for Databases lets user-controlled path parameters redirect downstream API requests beyond their intended scope. Environments using this tool to front database access should audit all tool configurations and apply available patches immediately.
6
Gorse's /api/dump and /api/restore endpoints skip authentication entirely when no admin_api_key is configured — which is the default — allowing any remote attacker to exfiltrate or overwrite the full database, including PII. A public PoC is already available, making exploitation trivial; all Gorse deployments below 0.5.10 should be treated as urgently exposed.
7
Authenticated users with destination management permissions in Coolify can inject arbitrary shell commands through the unvalidated 'network' parameter, executing as root on managed servers. This effectively grants full server compromise to any user with that permission level; patch to 4.0.0-beta.471 or later.
8
In Coolify's Nixpacks build pack, the install_command parameter is concatenated directly into shell commands without sanitization, enabling authenticated users to achieve root-level remote code execution on build hosts. Teams using Coolify for CI/CD pipelines face direct infrastructure compromise risk and should upgrade past 4.0.0-beta.470.
9
A use-after-free memory corruption bug in Safari's web content processing can be triggered by visiting a maliciously crafted page, potentially leading to arbitrary code execution on iOS, iPadOS, and macOS. Apple has addressed this in Safari 26.5.2, iOS 26.5.2, and macOS Tahoe 26.5.2 — apply updates promptly given the low interaction required from the victim.
10
A type confusion flaw in the same Apple web content stack as CVE-2026-43731 can similarly cause memory corruption when processing a crafted webpage, with potential code execution impact across Safari, iOS, iPadOS, and macOS. Both Apple bugs share the same fix release and should be treated as a paired update priority.
Today’s recommendation: Prioritize patching CVE-2026-56290 and CVE-2026-56782 today — the former requires zero credentials and the latter already has a public exploit proof-of-concept circulating. Simultaneously, push updates for all Coolify instances and Rancher clusters, and ensure Apple device fleets receive the 26.5.2 updates before end of business.
The breadth of platforms affected today — from CMS extensions and self-hosted DevOps tools to enterprise Kubernetes management and mobile browsers — underscores why regularly mapping and testing your own attack surface is essential to knowing which of these risks actually apply to your environment.Find out in minutes, with a free exposure assessment, where your organization is truly exposed.Meet the Autonomous AI Pentest Agent →Previous briefings
August 6, 2026 — 10 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026 — Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026 — Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026 — Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026 — Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026 — WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026 — Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 2026 — 32 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026 — Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026 — Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026 — CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026 — Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026 — CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026 — Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →