vulnerability Oracle’s Second Monthly Security Updates Deliver 245 Patches Oracle has released its June 2026 Critical Security Patch Update to fix vulnerabilities in Communications, EBS, Enterprise Manager and other products. The post Oracle’s Second Monthly Security Updates Deliver 245 Patches… SecurityWeek · Jun 17, 2026 Medium CVE-2026-35273
vulnerability Microsoft working on Defender patch for RoguePlanet zero-day Microsoft confirmed that it's working on a security patch for a Defender zero-day vulnerability named "RoguePlanet," disclosed one week ago. BleepingComputer · Jun 17, 2026 Critical CVE-2026-50656
vulnerability Chrome and Firefox Updated to Patch Critical, High-Severity Vulnerabilities The browser updates address multiple memory safety bugs that could potentially lead to remote code execution. The post Chrome and Firefox Updated to Patch Critical, High-Severity Vulnerabilities appeared first on Securit… SecurityWeek · Jun 17, 2026 High
vulnerability Joomla, LiteSpeed Vulnerabilities Exploited in Attacks The flaws allow attackers to execute arbitrary PHP code and gain root privileges on shared hosting servers. The post Joomla, LiteSpeed Vulnerabilities Exploited in Attacks appeared first on SecurityWeek . SecurityWeek · Jun 17, 2026 CVE-2026-48907CVE-2026-54420
vulnerability 3 Recently Patched Fortinet FortiSandbox Vulnerabilities in Hacker Crosshairs Recent analysis reveals that three previously patched Fortinet FortiSandbox vulnerabilities – CVE-2026-39808, CVE-2026-39813, and CVE-2026-25089 – are actively being exploited in the wild. A significant number of comprom… SecurityWeek · Jun 17, 2026 High CVE-2026-39808CVE-2026-39813CVE-2026-25089USINALvulnerabilitypatchingexploitation
vulnerability CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution CISA has added a critical vulnerability, CVE-2026-48907, to its Known Exploited Vulnerabilities catalog affecting the Widget Factory Joomla Content Editor (JCE) due to improper access control. This flaw allows for PHP co… The Hacker News · Jun 17, 2026 Critical CVE-2026-48907TUjoomlaphpcode execution
vulnerability Rockwell Automation FLEX I/O EtherNet/IP Adapters This CISA advisory details vulnerabilities within Rockwell Automation’s FLEX I/O EtherNet/IP Adapters (versions 2.012) that could allow unauthorized access and potential loss of device availability. The issues include a… CISA Advisories · Jun 16, 2026 High CVE-2026-0646CVE-2026-0647USethernet/ipcontrol systemsmemory corruption
vulnerability Rockwell Automation CompactLogix Rockwell Automation has issued a security advisory regarding vulnerabilities in its CompactLogix 5370 L1, L2, and L3 controllers. These vulnerabilities, stemming from improper validation of sequence numbers and source IP… CISA Advisories · Jun 16, 2026 Medium CVE-2025-11694CVE-2026-9307UScipdenial-of-serviceindustrial-control-systems
vulnerability Rockwell Automation FactoryTalk Analytics PavilionX This advisory from CISA details a critical vulnerability in Rockwell Automation’s FactoryTalk Analytics PavilionX software, specifically versions below 7.01. The flaw, stemming from improper authorization enforcement in… CISA Advisories · Jun 16, 2026 Critical CVE-2025-14272UScveauthorizationapi
vulnerability Rockwell Automation RSLinx Rockwell Automation has issued a security advisory regarding a vulnerability in its RSLinx Classic software. The flaw, a stack-based buffer overflow (CVE-2020-13573), allows for remote code execution and could lead to de… CISA Advisories · Jun 16, 2026 High CVE-2020-13573WObuffer overflowremote code executioncve-2020-13573
vulnerability CISA warns of another cPanel plugin flaw exploited in attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a critical vulnerability (CVE-2026-48172) in the LiteSpeed cPanel user-end plugin, which is currently being actively exploited.… BleepingComputer · Jun 16, 2026 Critical CVE-2026-54420CVE-2026-48172cpanelvulnerabilityprivilege escalation
vulnerability Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week Bad actors are exploiting multiple security vulnerabilities in Fortinet FortiSandbox, according to threat intelligence firm Defused Cyber. In a post shared on X, the company said it has observed exploitation of CVE-2026-… The Hacker News · Jun 16, 2026 Medium CVE-2026-39813CVE-2026-39808CVE-2026-25089
vulnerability Critical Fortinet FortiSandbox flaws now exploited in attacks Attackers are now exploiting several critical vulnerabilities in Fortinet's FortiSandbox cyber threat detection platform, according to threat intelligence company Defused. BleepingComputer · Jun 16, 2026 CVE-2026-39813CVE-2026-39808CVE-2026-25089
vulnerability Cisco Patches Another SD-WAN Zero-Day Exploited in Attacks Cisco recently became aware of the exploitation of CVE-2026-20262, a Catalyst SD-WAN Manager zero-day that allows arbitrary file write. The post Cisco Patches Another SD-WAN Zero-Day Exploited in Attacks appeared first o… SecurityWeek · Jun 16, 2026 Critical CVE-2026-20262CVE-2026-20182CVE-2026-20127
vulnerability Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw A vulnerability (CVE-2026-20262) in Cisco Catalyst SD-WAN Manager has been actively exploited in the wild, allowing authenticated attackers to overwrite files on affected systems. The flaw stems from inadequate input val… The Hacker News · Jun 16, 2026 High CVE-2026-20262CVE-2026-20245CVE-2026-20182USsd-wancvefile-upload
vulnerability CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege Escalation The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a security flaw impacting LiteSpeed cPanel Plugin to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Bran… The Hacker News · Jun 16, 2026 High CVE-2026-54420
vulnerability SimpleHelp bug lets hackers create rogue remote support accounts A critical vulnerability (CVE-2026-48558) in SimpleHelp remote management software allows unauthorized users to create privileged technician accounts via OpenID Connect (OIDC) authentication. This flaw, combined with spe… BleepingComputer · Jun 15, 2026 Critical CVE-2026-48558oidcremote managementauthentication
vulnerability Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks Cisco has released a security update to address a critical zero-day vulnerability (CVE-2026-20262) in its SD-WAN vManage software, allowing attackers to gain root privileges. The flaw stems from improper input validation… BleepingComputer · Jun 15, 2026 Critical CVE-2026-20262CVE-2026-20133CVE-2026-20128zero-dayroot privilegefile upload
vulnerability LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers A critical vulnerability chain in LiteLLM, an open-source AI gateway, allows low-privilege users to escalate their permissions to full administrator and execute arbitrary code on the server. Researchers at Obsidian Secur… The Hacker News · Jun 15, 2026 Critical CVE-2026-47101CVE-2026-47102CVE-2026-40217USaiproxyprivilege escalation
vulnerability Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw Palo Alto Networks has revealed that it has observed "active exploitation" of a recently disclosed PAN-OS vulnerability by an unknown threat actor to obtain unauthorized access to GlobalProtect portals. The vulnerability… The Hacker News · Jun 15, 2026 Medium CVE-2026-0257