Daily briefing · June 29, 2026

Unauthenticated RCE in Joomla Extension Leads Monday's Batch of Six Critical CVEs

Automated Vexday summary · sources: NVD, CISA KEV, EPSS

June 29, 2026 brought 220 new vulnerabilities, six of them rated Critical, with no confirmed active exploitation yet — but several flaws are severe enough to demand immediate attention. A perfect-score CVSS 10.0 unauthenticated file-upload-to-RCE in a Joomla extension tops the list, joined by privilege escalation in Rancher, multiple critical issues in Coolify, and web-content memory corruption bugs in Apple's Safari, iOS, and iPadOS. With a public proof-of-concept already circulating for the Gorse authentication bypass, the window for safe remediation is narrowing fast.

Today’s brief
  • CVE-2026-56290 scores a perfect CVSS 10.0: unauthenticated file upload leads to full RCE on any Joomla site running Page Builder CK.
  • Coolify racks up three separate critical/high vulnerabilities (CVE-2026-57498, CVE-2026-34594, CVE-2026-34597) covering authorization bypass, command injection, and RCE — update immediately.
  • Gorse's authentication bypass (CVE-2026-56782) already has a public PoC, exposing all user data on default-configured instances with no admin key set.
  • Apple issued Safari/iOS/iPadOS 26.5.2 fixes for two memory corruption bugs (CVE-2026-43731, CVE-2026-43705) triggerable by visiting a malicious webpage.
6
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-56290CVSS 10affects JoomlaCK.fr Page Builder CK extension for Joomla
Any unauthenticated attacker can upload an executable file through the Page Builder CK extension for Joomla and achieve full remote code execution on the host — a maximum-severity risk that requires no credentials whatsoever. Sites running this extension should treat it as actively compromised until patched or disabled.
2
CVE-2026-57331CVSS 9.9affects Paid Videochat Turnkey Site
Arbitrary file deletion affecting Paid Videochat Turnkey Site versions up to 7.4.8 can allow an attacker to destroy critical files, potentially destabilizing or taking down the platform entirely. Operators of this software should update or restrict access immediately.
3
CVE-2026-57498CVSS 9.6affects coolify
Coolify's Livewire UI components accept server_id and destination_uuid from URL query parameters without validating team ownership, allowing authenticated users to access or manipulate servers belonging to other teams. This breaks multi-tenant isolation in self-hosted deployments and should be patched to version 4.0.0-beta.474 or later.
4
CVE-2026-41052CVSS 9.4affects Rancher
Users holding the Project Owner role in Rancher can abuse improper privilege handling to escalate to higher-level permissions across affected versions 2.12, 2.13, and 2.14. Organizations relying on Rancher's RBAC model for workload separation must apply the respective patch releases without delay.
5
CVE-2026-11720CVSS 9.3affects MCP Toolbox for Databases (googleapis/mcp-toolbox)
A path traversal flaw in the HTTP tool URL builder of MCP Toolbox for Databases lets user-controlled path parameters redirect downstream API requests beyond their intended scope. Environments using this tool to front database access should audit all tool configurations and apply available patches immediately.
6
CVE-2026-56782CVSS 9.3PoCaffects gorse
Gorse's /api/dump and /api/restore endpoints skip authentication entirely when no admin_api_key is configured — which is the default — allowing any remote attacker to exfiltrate or overwrite the full database, including PII. A public PoC is already available, making exploitation trivial; all Gorse deployments below 0.5.10 should be treated as urgently exposed.
7
CVE-2026-34594HIGH 8.8affects coolify
Authenticated users with destination management permissions in Coolify can inject arbitrary shell commands through the unvalidated 'network' parameter, executing as root on managed servers. This effectively grants full server compromise to any user with that permission level; patch to 4.0.0-beta.471 or later.
8
CVE-2026-34597HIGH 8.8affects coolify
In Coolify's Nixpacks build pack, the install_command parameter is concatenated directly into shell commands without sanitization, enabling authenticated users to achieve root-level remote code execution on build hosts. Teams using Coolify for CI/CD pipelines face direct infrastructure compromise risk and should upgrade past 4.0.0-beta.470.
9
CVE-2026-43731HIGH 8.8affects iOS and iPadOS
A use-after-free memory corruption bug in Safari's web content processing can be triggered by visiting a maliciously crafted page, potentially leading to arbitrary code execution on iOS, iPadOS, and macOS. Apple has addressed this in Safari 26.5.2, iOS 26.5.2, and macOS Tahoe 26.5.2 — apply updates promptly given the low interaction required from the victim.
10
CVE-2026-43705HIGH 8.8affects iOS and iPadOS
A type confusion flaw in the same Apple web content stack as CVE-2026-43731 can similarly cause memory corruption when processing a crafted webpage, with potential code execution impact across Safari, iOS, iPadOS, and macOS. Both Apple bugs share the same fix release and should be treated as a paired update priority.
Today’s recommendation: Prioritize patching CVE-2026-56290 and CVE-2026-56782 today — the former requires zero credentials and the latter already has a public exploit proof-of-concept circulating. Simultaneously, push updates for all Coolify instances and Rancher clusters, and ensure Apple device fleets receive the 26.5.2 updates before end of business.
The breadth of platforms affected today — from CMS extensions and self-hosted DevOps tools to enterprise Kubernetes management and mobile browsers — underscores why regularly mapping and testing your own attack surface is essential to knowing which of these risks actually apply to your environment.Find out in minutes, with a free exposure assessment, where your organization is truly exposed.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 20, 2026Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active ExploitationSeptember 16, 2026Cisco Infrastructure Flooded With CVSS 10 Flaws as VulnCheck Spots Active Exploitation Before CISASeptember 15, 2026Oracle Patch Tuesday Surge and Yonyou Active Exploitation Drive ATTENTION-Level AlertSeptember 14, 2026Cisco Secure Email Under Active Exploitation as 58 Critical CVEs SurfaceSeptember 13, 2026WordPress Plugin Flaw Leads Quiet Day With 8 Critical CVEs and No Active ExploitationSeptember 12, 2026WordPress Plugin Blitz: Nine Critical RCE and Takeover Flaws Disclosed on a Quiet Exploit DaySeptember 11, 2026GitLab Critical Zero-Day Under Active Exploitation Leads a Heavy Patch Day with 36 Critical CVEsSeptember 10, 2026Ten Critical CVEs Published on a Calm Threat Day as Brazil Faces Ransomware SurgeSeptember 9, 2026Three CVEs Already Exploited Before CISA Confirmation, Dual Check Point RCE and cPanel SQLi-to-Root Round Out a High-Alert DaySeptember 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on Brazilview full archive →
Share