Daily briefing · June 29, 2026

Unauthenticated RCE in Joomla Extension Leads Monday's Batch of Six Critical CVEs

Automated Vexday summary · sources: NVD, CISA KEV, EPSS

June 29, 2026 brought 220 new vulnerabilities, six of them rated Critical, with no confirmed active exploitation yet — but several flaws are severe enough to demand immediate attention. A perfect-score CVSS 10.0 unauthenticated file-upload-to-RCE in a Joomla extension tops the list, joined by privilege escalation in Rancher, multiple critical issues in Coolify, and web-content memory corruption bugs in Apple's Safari, iOS, and iPadOS. With a public proof-of-concept already circulating for the Gorse authentication bypass, the window for safe remediation is narrowing fast.

Today’s brief
  • CVE-2026-56290 scores a perfect CVSS 10.0: unauthenticated file upload leads to full RCE on any Joomla site running Page Builder CK.
  • Coolify racks up three separate critical/high vulnerabilities (CVE-2026-57498, CVE-2026-34594, CVE-2026-34597) covering authorization bypass, command injection, and RCE — update immediately.
  • Gorse's authentication bypass (CVE-2026-56782) already has a public PoC, exposing all user data on default-configured instances with no admin key set.
  • Apple issued Safari/iOS/iPadOS 26.5.2 fixes for two memory corruption bugs (CVE-2026-43731, CVE-2026-43705) triggerable by visiting a malicious webpage.
6
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-56290CVSS 10affects JoomlaCK.fr Page Builder CK extension for Joomla
Any unauthenticated attacker can upload an executable file through the Page Builder CK extension for Joomla and achieve full remote code execution on the host — a maximum-severity risk that requires no credentials whatsoever. Sites running this extension should treat it as actively compromised until patched or disabled.
2
CVE-2026-57331CVSS 9.9affects Paid Videochat Turnkey Site
Arbitrary file deletion affecting Paid Videochat Turnkey Site versions up to 7.4.8 can allow an attacker to destroy critical files, potentially destabilizing or taking down the platform entirely. Operators of this software should update or restrict access immediately.
3
CVE-2026-57498CVSS 9.6affects coolify
Coolify's Livewire UI components accept server_id and destination_uuid from URL query parameters without validating team ownership, allowing authenticated users to access or manipulate servers belonging to other teams. This breaks multi-tenant isolation in self-hosted deployments and should be patched to version 4.0.0-beta.474 or later.
4
CVE-2026-41052CVSS 9.4affects Rancher
Users holding the Project Owner role in Rancher can abuse improper privilege handling to escalate to higher-level permissions across affected versions 2.12, 2.13, and 2.14. Organizations relying on Rancher's RBAC model for workload separation must apply the respective patch releases without delay.
5
CVE-2026-11720CVSS 9.3affects MCP Toolbox for Databases (googleapis/mcp-toolbox)
A path traversal flaw in the HTTP tool URL builder of MCP Toolbox for Databases lets user-controlled path parameters redirect downstream API requests beyond their intended scope. Environments using this tool to front database access should audit all tool configurations and apply available patches immediately.
6
CVE-2026-56782CVSS 9.3PoCaffects gorse
Gorse's /api/dump and /api/restore endpoints skip authentication entirely when no admin_api_key is configured — which is the default — allowing any remote attacker to exfiltrate or overwrite the full database, including PII. A public PoC is already available, making exploitation trivial; all Gorse deployments below 0.5.10 should be treated as urgently exposed.
7
CVE-2026-34594HIGH 8.8affects coolify
Authenticated users with destination management permissions in Coolify can inject arbitrary shell commands through the unvalidated 'network' parameter, executing as root on managed servers. This effectively grants full server compromise to any user with that permission level; patch to 4.0.0-beta.471 or later.
8
CVE-2026-34597HIGH 8.8affects coolify
In Coolify's Nixpacks build pack, the install_command parameter is concatenated directly into shell commands without sanitization, enabling authenticated users to achieve root-level remote code execution on build hosts. Teams using Coolify for CI/CD pipelines face direct infrastructure compromise risk and should upgrade past 4.0.0-beta.470.
9
CVE-2026-43731HIGH 8.8affects iOS and iPadOS
A use-after-free memory corruption bug in Safari's web content processing can be triggered by visiting a maliciously crafted page, potentially leading to arbitrary code execution on iOS, iPadOS, and macOS. Apple has addressed this in Safari 26.5.2, iOS 26.5.2, and macOS Tahoe 26.5.2 — apply updates promptly given the low interaction required from the victim.
10
CVE-2026-43705HIGH 8.8affects iOS and iPadOS
A type confusion flaw in the same Apple web content stack as CVE-2026-43731 can similarly cause memory corruption when processing a crafted webpage, with potential code execution impact across Safari, iOS, iPadOS, and macOS. Both Apple bugs share the same fix release and should be treated as a paired update priority.
Today’s recommendation: Prioritize patching CVE-2026-56290 and CVE-2026-56782 today — the former requires zero credentials and the latter already has a public exploit proof-of-concept circulating. Simultaneously, push updates for all Coolify instances and Rancher clusters, and ensure Apple device fleets receive the 26.5.2 updates before end of business.
The breadth of platforms affected today — from CMS extensions and self-hosted DevOps tools to enterprise Kubernetes management and mobile browsers — underscores why regularly mapping and testing your own attack surface is essential to knowing which of these risks actually apply to your environment.Find out in minutes, with a free exposure assessment, where your organization is truly exposed.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 202610 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →
Share