Fortinet patches unauth command injection in FortiSandbox (CVE-2026-25089)
Crafted HTTP requests against the FortiSandbox web UI yield OS command execution. CVSS 9.1. No active exploitation reported. Fixed in 5.0.6 and 4.4.9.
Crafted HTTP requests against the FortiSandbox web UI yield OS command execution. CVSS 9.1. No active exploitation reported. Fixed in 5.0.6 and 4.4.9.
VulnCheck added CVE-2026-5027 to its KEV on June 8 after detecting in-the-wild exploitation. Path traversal in /api/v2/files yields unauth RCE; ~7,000 instances are publicly exposed.
Wordfence's firewall blocked 29,300+ exploit attempts against a CVSS 9.8 PHP-eval RCE in Everest Forms Pro. Sites pre-1.9.13 should hunt for the rogue admin diksimarina.
Oracle ships an out-of-band Security Alert for an unauthenticated RCE in PeopleTools 8.61/8.62. Mandiant ties exploitation since May 27 to ShinyHunters (UNC6240).
Tunnel-decap logic flaw in Arista EOS lets crafted VXLAN/GRE/decap-group packets reach configured decap IPs. Exploited in the wild. Arista will not patch — mitigate with ACLs.
Microsoft's June 9 Patch Tuesday fixes around 200 CVEs and 33 Critical flaws, including publicly disclosed zero-days in BitLocker, HTTP.sys (HTTP/2 Bomb) and CTFMON.
An authenticated domain user can run code on a domain-joined VBR backup server. CVSS 9.4. Fixed in 12.3.2.4854; v13 is not affected.
Check Point hotfixes a CVSS 9.3 cert-validation bypass on Remote Access and Mobile Access VPN. Exploitation since May 7, 2026 — one case linked to a Qilin affiliate.
Exodus Intelligence published a complete local root exploit for CVE-2026-23111 — a one-character nf_tables UAF patched upstream Feb 5. Container escape on default distros.