Daily briefing · June 29, 2026

Unauthenticated RCE in Joomla Extension Leads Monday's Batch of Six Critical CVEs

Automated Vexday summary · sources: NVD, CISA KEV, EPSS

June 29, 2026 brought 220 new vulnerabilities, six of them rated Critical, with no confirmed active exploitation yet — but several flaws are severe enough to demand immediate attention. A perfect-score CVSS 10.0 unauthenticated file-upload-to-RCE in a Joomla extension tops the list, joined by privilege escalation in Rancher, multiple critical issues in Coolify, and web-content memory corruption bugs in Apple's Safari, iOS, and iPadOS. With a public proof-of-concept already circulating for the Gorse authentication bypass, the window for safe remediation is narrowing fast.

Today’s brief
  • CVE-2026-56290 scores a perfect CVSS 10.0: unauthenticated file upload leads to full RCE on any Joomla site running Page Builder CK.
  • Coolify racks up three separate critical/high vulnerabilities (CVE-2026-57498, CVE-2026-34594, CVE-2026-34597) covering authorization bypass, command injection, and RCE — update immediately.
  • Gorse's authentication bypass (CVE-2026-56782) already has a public PoC, exposing all user data on default-configured instances with no admin key set.
  • Apple issued Safari/iOS/iPadOS 26.5.2 fixes for two memory corruption bugs (CVE-2026-43731, CVE-2026-43705) triggerable by visiting a malicious webpage.
6
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-56290CVSS 10affects JoomlaCK.fr Page Builder CK extension for Joomla
Any unauthenticated attacker can upload an executable file through the Page Builder CK extension for Joomla and achieve full remote code execution on the host — a maximum-severity risk that requires no credentials whatsoever. Sites running this extension should treat it as actively compromised until patched or disabled.
2
CVE-2026-57331CVSS 9.9affects Paid Videochat Turnkey Site
Arbitrary file deletion affecting Paid Videochat Turnkey Site versions up to 7.4.8 can allow an attacker to destroy critical files, potentially destabilizing or taking down the platform entirely. Operators of this software should update or restrict access immediately.
3
CVE-2026-57498CVSS 9.6affects coolify
Coolify's Livewire UI components accept server_id and destination_uuid from URL query parameters without validating team ownership, allowing authenticated users to access or manipulate servers belonging to other teams. This breaks multi-tenant isolation in self-hosted deployments and should be patched to version 4.0.0-beta.474 or later.
4
CVE-2026-41052CVSS 9.4affects Rancher
Users holding the Project Owner role in Rancher can abuse improper privilege handling to escalate to higher-level permissions across affected versions 2.12, 2.13, and 2.14. Organizations relying on Rancher's RBAC model for workload separation must apply the respective patch releases without delay.
5
CVE-2026-11720CVSS 9.3affects MCP Toolbox for Databases (googleapis/mcp-toolbox)
A path traversal flaw in the HTTP tool URL builder of MCP Toolbox for Databases lets user-controlled path parameters redirect downstream API requests beyond their intended scope. Environments using this tool to front database access should audit all tool configurations and apply available patches immediately.
6
CVE-2026-56782CVSS 9.3PoCaffects gorse
Gorse's /api/dump and /api/restore endpoints skip authentication entirely when no admin_api_key is configured — which is the default — allowing any remote attacker to exfiltrate or overwrite the full database, including PII. A public PoC is already available, making exploitation trivial; all Gorse deployments below 0.5.10 should be treated as urgently exposed.
7
CVE-2026-34594HIGH 8.8affects coolify
Authenticated users with destination management permissions in Coolify can inject arbitrary shell commands through the unvalidated 'network' parameter, executing as root on managed servers. This effectively grants full server compromise to any user with that permission level; patch to 4.0.0-beta.471 or later.
8
CVE-2026-34597HIGH 8.8affects coolify
In Coolify's Nixpacks build pack, the install_command parameter is concatenated directly into shell commands without sanitization, enabling authenticated users to achieve root-level remote code execution on build hosts. Teams using Coolify for CI/CD pipelines face direct infrastructure compromise risk and should upgrade past 4.0.0-beta.470.
9
CVE-2026-43731HIGH 8.8affects iOS and iPadOS
A use-after-free memory corruption bug in Safari's web content processing can be triggered by visiting a maliciously crafted page, potentially leading to arbitrary code execution on iOS, iPadOS, and macOS. Apple has addressed this in Safari 26.5.2, iOS 26.5.2, and macOS Tahoe 26.5.2 — apply updates promptly given the low interaction required from the victim.
10
CVE-2026-43705HIGH 8.8affects iOS and iPadOS
A type confusion flaw in the same Apple web content stack as CVE-2026-43731 can similarly cause memory corruption when processing a crafted webpage, with potential code execution impact across Safari, iOS, iPadOS, and macOS. Both Apple bugs share the same fix release and should be treated as a paired update priority.
Today’s recommendation: Prioritize patching CVE-2026-56290 and CVE-2026-56782 today — the former requires zero credentials and the latter already has a public exploit proof-of-concept circulating. Simultaneously, push updates for all Coolify instances and Rancher clusters, and ensure Apple device fleets receive the 26.5.2 updates before end of business.
The breadth of platforms affected today — from CMS extensions and self-hosted DevOps tools to enterprise Kubernetes management and mobile browsers — underscores why regularly mapping and testing your own attack surface is essential to knowing which of these risks actually apply to your environment.Find out in minutes, with a free exposure assessment, where your organization is truly exposed.Meet the Autonomous AI Pentest Agent →
Previous briefings
August 6, 202610 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 202632 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →