Daily briefing · June 27, 2026
Ten KEV-Confirmed Vulnerabilities Dominate the Spotlight: Joomla, PeopleSoft, Splunk, and More Under Active Exploitation
June 27, 2026 recorded no new CVE publications, but the threat landscape remains sharp: all ten vulnerabilities highlighted today carry confirmed active exploitation status (KEV), spanning web CMS plugins, enterprise ERP platforms, SIEM infrastructure, VPN gateways, browsers, and network controllers. The combination of unauthenticated attack vectors, public proof-of-concept code, and high EPSS scores across the board makes this a high-urgency patch cycle for defenders. Organizations still running unpatched instances of any affected product face immediate, realistic risk of compromise.
Today’s brief
- All 10 featured CVEs are under active exploitation (KEV-confirmed) with public PoC code available — patching is not optional.
- Two vulnerabilities (Joomla JCE and Oracle PeopleSoft) carry CVSS 10.0 and 9.8 respectively, allowing full unauthenticated remote takeover.
- Splunk Enterprise and Quantum Security Gateway flaws enable unauthenticated file manipulation and VPN authentication bypass at scale.
- Network infrastructure (Cisco SD-WAN, Arista EOS, SolarWinds Serv-U) is also in the crosshairs, extending risk beyond traditional application layers.
Critical highlights
1
A critical CVSS 10.0 flaw in the JCE editor extension for Joomla lets completely unauthenticated attackers create editor profiles and upload arbitrary PHP code for server-side execution — full remote code execution with zero credentials required on any exposed Joomla site running JCE.
2
Oracle PeopleSoft (PeopleTools 8.61/8.62) exposes a CVSS 9.8 unauthenticated network-accessible endpoint that allows complete system takeover via HTTP; with 90% EPSS and a public PoC, automated exploitation at scale is a near-certainty for unpatched deployments.
3
Splunk Enterprise versions below 10.2.4 and 10.0.7 expose a PostgreSQL sidecar service endpoint with no authentication, letting any network-reachable attacker create or truncate arbitrary files — a direct path to data destruction or code execution on the Splunk host.
4
A logic flaw in deprecated IKEv1 certificate validation on Quantum Security Gateways allows unauthenticated remote attackers to fully bypass user authentication and establish VPN connections without valid credentials — effectively granting attackers the same access level as legitimate remote users.
5
An out-of-bounds read/write in Chrome's V8 JavaScript engine (versions before 149.0.7827.103) can be triggered by a crafted HTML page, achieving arbitrary code execution inside the browser sandbox — a browser-delivered exploit requiring only that a user visits a malicious or compromised site.
6
The LiteSpeed cPanel plugin before 2.4.8 mishandles symlinks on shared hosting servers, allowing any user with FTP or web shell access to escape CloudLinux/CageFS containment and impact other tenants on the same host — a critical shared-hosting isolation failure actively exploited since May 2026.
7
An integer overflow in Android's core platform enables local privilege escalation to higher execution levels without any additional permissions or user interaction — making it a reliable post-access escalation tool for malware or malicious apps already running on a device.
8
Authenticated local attackers on Cisco Catalyst SD-WAN Controller, Manager, or Validator can escalate to root by supplying a crafted file to the CLI — in SD-WAN environments where multiple administrators share access, this flaw breaks the principle of least privilege and enables full infrastructure control.
9
SolarWinds Serv-U crashes when it receives specially crafted unauthenticated POST requests using Content-Encoding: deflate — a trivially reproducible denial-of-service that requires no credentials and can be weaponized to disrupt managed file transfer operations continuously.
10
Arista EOS platforms with VXLAN, decap-group, or GRE tunnel configurations will incorrectly decapsulate and forward unexpected tunneled packets to any destination IP matching a configured decap address, enabling traffic injection and potential network segmentation bypass without authentication.
Today’s recommendation: Prioritize immediate patching of CVE-2026-48907, CVE-2026-35273, and CVE-2026-20253 given their unauthenticated attack vectors, CVSS scores at or above 9.8, and confirmed in-the-wild exploitation; for assets that cannot be patched immediately, apply network-level controls to restrict access to affected services and monitor for anomalous file creation, authentication, and tunnel traffic patterns.
With ten actively exploited vulnerabilities spanning web applications, enterprise platforms, network controllers, and end-user browsers, now is the right moment to validate which of these products exist in your environment and whether your current controls would detect or block exploitation attempts before an attacker does.New vulnerabilities surface every day — does your defense keep up? Get a free initial review of your attack surface.Meet the Autonomous AI Pentest Agent →Previous briefings
September 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026 — Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026 — WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026 — WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026 — Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026 — WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026 — Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026 — WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026 — Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026 — Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 2026 — 10 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026 — Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026 — Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →