Daily briefing · June 26, 2026

10 Actively Exploited CVEs Dominate: Joomla RCE, Splunk File Write, and PeopleSoft Takeover Lead Critical Wave

Automated Vexday summary · sources: NVD, CISA KEV, EPSS

Although June 26, 2026 registered no new CVE publications, defenders face a dense landscape of actively exploited vulnerabilities spanning enterprise platforms, network infrastructure, and end-user software. All ten highlighted entries carry KEV status, meaning real-world exploitation has been confirmed, demanding immediate prioritization. The breadth of affected products — from CMS extensions and SIEM platforms to SD-WAN controllers and mobile operating systems — underscores how heterogeneous the current threat surface truly is.

Today’s brief
  • All 10 featured CVEs are confirmed under active exploitation (KEV), with public PoCs available for every one of them.
  • Three vulnerabilities score CVSS 9.8 or higher: unauthenticated RCE or full system takeover is achievable without credentials in Joomla JCE, Splunk Enterprise, and Oracle PeopleSoft.
  • VPN authentication bypass in Quantum Security Gateway and a Chrome V8 out-of-bounds RCE add browser and remote-access risk to the mix.
  • Cisco SD-WAN, SolarWinds Serv-U, Android, LiteSpeed cPanel plugin, and Arista EOS round out a wide-ranging set of critical patching obligations.
Critical highlights
1
CVE-2026-48907KEVCVSS 10PoCaffects Joomla Content Editor (JCE) extension for Joomla
An unauthenticated attacker can create new editor profiles in the JCE extension for Joomla and leverage that to upload and execute arbitrary PHP code on the web server — effectively a zero-click remote code execution path for any publicly reachable Joomla site running JCE.
2
CVE-2026-20253KEVCVSS 9.8PoCaffects Splunk Enterprise
Splunk Enterprise exposes a PostgreSQL sidecar service endpoint with no authentication, letting any network-reachable user create or truncate arbitrary files; in practice this can be chained to overwrite configuration or executable files and achieve code execution on the Splunk server.
3
CVE-2026-35273KEVCVSS 9.8PoCaffects PeopleSoft Enterprise PeopleTools
This unauthenticated, network-accessible flaw in Oracle PeopleSoft PeopleTools (versions 8.61 and 8.62) can result in complete takeover of the PeopleSoft instance, putting HR, financial, and ERP data at direct risk with no credentials required.
4
CVE-2026-50751KEVCVSS 9.3PoCaffects Quantum Security Gateway
A logic flaw in deprecated IKEv1 certificate validation in Quantum Security Gateway allows an unauthenticated remote attacker to bypass VPN authentication entirely, establishing a full remote access session without a valid password — a critical exposure for organizations relying on this gateway for perimeter control.
5
CVE-2026-11645KEVHIGH 8.8PoCaffects Chrome
An out-of-bounds read and write in Chrome's V8 JavaScript engine enables arbitrary code execution inside the browser sandbox via a malicious web page, affecting all Chrome versions prior to 149.0.7827.103 and exposing any user who browses to attacker-controlled content.
6
CVE-2026-54420KEVHIGH 8.5PoCaffects cPanel Plugin
The LiteSpeed cPanel plugin mishandles symlinks supplied by users with FTP or web shell access on shared hosting servers running CloudLinux/CageFS, allowing privilege escalation beyond CageFS boundaries — a significant risk for hosting providers with untrusted tenants.
7
CVE-2025-48595KEVHIGH 8.4PoCaffects Android
An integer overflow in multiple Android system locations allows local privilege escalation to higher execution contexts with no additional privileges or user interaction required, making it a practical tool for malicious apps or post-exploitation persistence on unpatched Android devices.
8
CVE-2026-20245KEVHIGH 7.8PoCaffects Cisco Catalyst SD-WAN Controller
An authenticated local attacker on Cisco Catalyst SD-WAN Controller, Manager, or Validator can supply a crafted file to the CLI and execute arbitrary commands as root, converting any compromised local account into full infrastructure control over SD-WAN fabric components.
9
CVE-2026-28318KEVHIGH 7.5PoCaffects Serv-U
SolarWinds Serv-U crashes when it receives a specially crafted unauthenticated POST request using Content-Encoding: deflate, creating a reliable denial-of-service vector against file transfer infrastructure without requiring any credentials.
10
CVE-2026-7473KEVMEDIUM 6.9PoCaffects EOS
Affected Arista EOS switches with VXLAN, decap-group, or GRE tunnel configurations will incorrectly decapsulate and forward unexpected tunneled packets destined for the device's decapsulation IP, potentially enabling traffic injection or network segmentation bypass by an attacker who can reach the switch.
Today’s recommendation: Organizations should immediately verify patch status for all ten CVEs against their asset inventory, prioritizing CVE-2026-48907, CVE-2026-20253, and CVE-2026-35273 given their CVSS 9.8–10.0 scores and confirmed active exploitation; where patching cannot be applied instantly, network-level controls such as blocking unauthenticated access to exposed service endpoints and disabling deprecated IKEv1 should be enforced as interim mitigations.
With confirmed exploitation confirmed across this many product families simultaneously, the most pressing question for any security team is whether their own asset inventory accurately reflects which of these systems are internet-exposed — validating that surface from the outside in is the fastest way to prioritize what needs attention first.Knowing the flaw exists is half the job; the other half is knowing if it affects you. Start with a no-cost exposure test.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 202610 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →
Share