Daily briefing · June 26, 2026
10 Actively Exploited CVEs Dominate: Joomla RCE, Splunk File Write, and PeopleSoft Takeover Lead Critical Wave
Although June 26, 2026 registered no new CVE publications, defenders face a dense landscape of actively exploited vulnerabilities spanning enterprise platforms, network infrastructure, and end-user software. All ten highlighted entries carry KEV status, meaning real-world exploitation has been confirmed, demanding immediate prioritization. The breadth of affected products — from CMS extensions and SIEM platforms to SD-WAN controllers and mobile operating systems — underscores how heterogeneous the current threat surface truly is.
Today’s brief
- All 10 featured CVEs are confirmed under active exploitation (KEV), with public PoCs available for every one of them.
- Three vulnerabilities score CVSS 9.8 or higher: unauthenticated RCE or full system takeover is achievable without credentials in Joomla JCE, Splunk Enterprise, and Oracle PeopleSoft.
- VPN authentication bypass in Quantum Security Gateway and a Chrome V8 out-of-bounds RCE add browser and remote-access risk to the mix.
- Cisco SD-WAN, SolarWinds Serv-U, Android, LiteSpeed cPanel plugin, and Arista EOS round out a wide-ranging set of critical patching obligations.
Critical highlights
1
An unauthenticated attacker can create new editor profiles in the JCE extension for Joomla and leverage that to upload and execute arbitrary PHP code on the web server — effectively a zero-click remote code execution path for any publicly reachable Joomla site running JCE.
2
Splunk Enterprise exposes a PostgreSQL sidecar service endpoint with no authentication, letting any network-reachable user create or truncate arbitrary files; in practice this can be chained to overwrite configuration or executable files and achieve code execution on the Splunk server.
3
This unauthenticated, network-accessible flaw in Oracle PeopleSoft PeopleTools (versions 8.61 and 8.62) can result in complete takeover of the PeopleSoft instance, putting HR, financial, and ERP data at direct risk with no credentials required.
4
A logic flaw in deprecated IKEv1 certificate validation in Quantum Security Gateway allows an unauthenticated remote attacker to bypass VPN authentication entirely, establishing a full remote access session without a valid password — a critical exposure for organizations relying on this gateway for perimeter control.
5
An out-of-bounds read and write in Chrome's V8 JavaScript engine enables arbitrary code execution inside the browser sandbox via a malicious web page, affecting all Chrome versions prior to 149.0.7827.103 and exposing any user who browses to attacker-controlled content.
6
The LiteSpeed cPanel plugin mishandles symlinks supplied by users with FTP or web shell access on shared hosting servers running CloudLinux/CageFS, allowing privilege escalation beyond CageFS boundaries — a significant risk for hosting providers with untrusted tenants.
7
An integer overflow in multiple Android system locations allows local privilege escalation to higher execution contexts with no additional privileges or user interaction required, making it a practical tool for malicious apps or post-exploitation persistence on unpatched Android devices.
8
An authenticated local attacker on Cisco Catalyst SD-WAN Controller, Manager, or Validator can supply a crafted file to the CLI and execute arbitrary commands as root, converting any compromised local account into full infrastructure control over SD-WAN fabric components.
9
SolarWinds Serv-U crashes when it receives a specially crafted unauthenticated POST request using Content-Encoding: deflate, creating a reliable denial-of-service vector against file transfer infrastructure without requiring any credentials.
10
Affected Arista EOS switches with VXLAN, decap-group, or GRE tunnel configurations will incorrectly decapsulate and forward unexpected tunneled packets destined for the device's decapsulation IP, potentially enabling traffic injection or network segmentation bypass by an attacker who can reach the switch.
Today’s recommendation: Organizations should immediately verify patch status for all ten CVEs against their asset inventory, prioritizing CVE-2026-48907, CVE-2026-20253, and CVE-2026-35273 given their CVSS 9.8–10.0 scores and confirmed active exploitation; where patching cannot be applied instantly, network-level controls such as blocking unauthenticated access to exposed service endpoints and disabling deprecated IKEv1 should be enforced as interim mitigations.
With confirmed exploitation confirmed across this many product families simultaneously, the most pressing question for any security team is whether their own asset inventory accurately reflects which of these systems are internet-exposed — validating that surface from the outside in is the fastest way to prioritize what needs attention first.Knowing the flaw exists is half the job; the other half is knowing if it affects you. Start with a no-cost exposure test.Meet the Autonomous AI Pentest Agent →Previous briefings
September 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026 — Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026 — WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026 — WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026 — Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026 — WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026 — Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026 — WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026 — Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026 — Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 2026 — 10 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026 — Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026 — Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →