ServiceNow's July 13 patch closes CVE-2026-6875 — a pre-auth sandbox escape in the AI Platform that yields unauthenticated RCE. Defused observed in-the-wild exploitation five days later.
Zimbra shipped Daffodil 10.1.20 with a critical command injection in the SNMP monitor, four Classic UI XSS bugs, an SSRF in Nextcloud, and CVE-2026-50055 / CVE-2026-10631 / CVE-2026-50054.
CISA added SonicWall SMA1000 zero-days CVE-2026-15409 (SSRF, CVSS 10.0) and CVE-2026-15410 to KEV on July 14, chained by Rapid7 MDR. Federal deadline July 17.
SAP's July 14 Patch Day ships 16 notes: a NetWeaver ABAP memory-corruption bug at CVSS 9.9, an Approuter request-smuggling flaw and Commerce Cloud default credentials both at 9.1.
Zimbra shipped Daffodil 10.1.19 on July 7 to fix a stored XSS in the Classic Web Client where a crafted email runs JavaScript in the recipient's mailbox session. Reporter: Google TAG. No CVE assigned.
CERT/CC disclosed CVE-2026-11405 on July 6: five Tenda firmware images ship a plaintext strcmp() backdoor in /bin/httpd. Tenda didn't respond and no patch is available.
Ubiquiti's SAB-066 patches 25 UniFi flaws led by CVE-2026-50746 — an unauthenticated command injection in Connect ≤3.4.16 (CVSS 10.0). Fix ships in Connect 3.4.20.
Seven FatFs bugs disclosed July 1 by runZero — FAT32, exFAT and long-filename paths across ESP-IDF, STM32Cube, Zephyr, MicroPython. Only CVE-2026-6684 has an upstream fix.
Defused honeypots caught in-the-wild exploitation of CVE-2026-46817 (CVSS 9.8) on June 27, six weeks after Oracle's May patch. ~950 EBS instances are internet-exposed.
Progress patches an unauth pre-auth command-injection RCE in Kemp LoadMaster. CVSS 9.8. GA 7.2.63.2 and LTSF 7.2.54.18 ship the fix; watchTowr posted the full chain on June 29.
OpenAM 16.1.1 shipped June 17 with fixes for 17 CVEs. Public advisories began June 22 and continued through June 29: pre-auth RADIUS spoof, MSISDN LDAP injection, OAuth2 takeover, Groovy sandbox RCE.
FBI PSA I-062626-PSA names UNC5792 and UNC4221, attributes the activity to Russian Intelligence Services, and adds a new Signal Backup Recovery Key phishing tactic to the March warning.
CISA gave federal agencies three days to patch the Bulletin 064 UniFi OS triple — access control bypass, path traversal, command injection — all CVSS 10.0, all exploited.
CISA added the CVSS 9.8 command-injection bug — plus three perfect-10 UniFi OS flaws — to KEV on June 23. BOD 26-04 forces federal patching by June 26.
CISA added the CVSS 10 deserialization RCE in Windchill PDMLink and FlexPLM to KEV on June 25. PTC ships patches, BSI repeats the alarm. Three days to act.
Squid project published SQUID-2026:4 on June 23 — a heap over-read in the FTP gateway that leaks raw memory to a malicious FTP server. Fix in Squid 7.6.
CVE-2026-20253 is a CVSS 9.8 missing-authentication flaw in Splunk Enterprise 10. CISA added it to KEV on June 18 with a three-day patch deadline. WatchTowr published a working RCE exploit.
Node.js v22.23.0, v24.17.0 and v26.3.1 fix 12 CVEs including a TLS wildcard hostname bypass (CVE-2026-48618) and a WebCrypto integer overflow DoS (CVE-2026-48933).
Wordfence blocked 17M attempts at the unauth REST endpoint that dumps Gravity SMTP's full System Report — live API keys and OAuth tokens included. Patch is 2.1.5.
Aikido Security found 15 JetBrains Marketplace plugins under 7 vendor accounts that exfiltrated OpenAI, DeepSeek, and SiliconFlow keys over plaintext HTTP. JetBrains pulled them on June 16, 2026.
SurrealDB shipped 3.1.5 on June 19, closing five same-day GitHub advisories — including arbitrary file read via DEFINE ANALYZER mapper at CVSS 7.7. No CVE IDs assigned yet.
Researcher Bob Diachenko found an open attacker server holding plaintext admin and SSL VPN credentials for 73,932 FortiGate appliances across 194 countries. CISA issued reset guidance June 18.
F5 shipped NGINX 1.31.2 and 1.30.3 on June 17 fixing a use-after-free in the HTTP/3 module, a heap overflow in proxy_v2/grpc, and a buffer overread in charset.
Second Cisco Catalyst SD-WAN Manager zero-day in two weeks. CVE-2026-20262 is an arbitrary file write under exploitation; CISA gave agencies until June 29 to patch.
CISA added CVE-2026-48907 to KEV on June 16 — an unauth profile-import chain in the JCE Joomla extension that lets attackers upload and execute PHP. Patch in JCE 2.9.99.5.
VulnCheck added CVE-2026-5027 to its KEV on June 8 after detecting in-the-wild exploitation. Path traversal in /api/v2/files yields unauth RCE; ~7,000 instances are publicly exposed.
Wordfence's firewall blocked 29,300+ exploit attempts against a CVSS 9.8 PHP-eval RCE in Everest Forms Pro. Sites pre-1.9.13 should hunt for the rogue admin diksimarina.
Tunnel-decap logic flaw in Arista EOS lets crafted VXLAN/GRE/decap-group packets reach configured decap IPs. Exploited in the wild. Arista will not patch — mitigate with ACLs.
Microsoft's June 9 Patch Tuesday fixes around 200 CVEs and 33 Critical flaws, including publicly disclosed zero-days in BitLocker, HTTP.sys (HTTP/2 Bomb) and CTFMON.
Check Point hotfixes a CVSS 9.3 cert-validation bypass on Remote Access and Mobile Access VPN. Exploitation since May 7, 2026 — one case linked to a Qilin affiliate.
GMO Flatt Security's RyotaK chained a checkWritePermissions bot bypass with prompt injection to hijack any public repo running claude-code-action. Fix shipped in v1.0.94.
Cisco disclosed a command-injection zero-day in Catalyst SD-WAN Manager on June 5. Mandiant credited as reporter. CVSS 7.8, exploitation observed, no fix available.
Researcher Ammar Askar dropped a webview-postMessage exploit on June 2 that steals github.dev OAuth tokens via a single click. Microsoft shipped a stopgap fix the next day.
Red Hat security bulletin RHSB-2026-006 confirms 32 @redhat-cloud-services npm packages were trojaned on June 1, 2026 with a self-spreading credential-stealing worm derived from Shai-Hulud.
Microsoft says a single maintainer 'vpmdhaj' pushed 14 typosquatted npm packages on May 28 that exfiltrate AWS, ECS, HashiCorp Vault and npm tokens via a Bun-runtime payload.
PAN-OS portals with authentication-override cookies on a shared certificate let attackers forge a valid session. Rapid7 observed exploitation since May 17. Federal patch deadline June 19.
An unauthenticated SQL injection in Ghost's Content API leaks admin API keys. Attackers chain it into stored XSS and a fake Cloudflare ClickFix lure. Upgrade to 6.19.1.
An unauthenticated SQL injection in Drupal core's database abstraction API affects every PostgreSQL-backed site. Drupal scored it 23/25. Attacks started two days after the patch dropped.
Attackers rewrote Git tags across four Laravel-Lang repos to point at a malicious fork, planting a Composer-autoloaded stealer that runs on every request. Packagist has unlisted the packages.
A privilege-escalation flaw in the LiteSpeed User-End cPanel plugin lets any cPanel account execute arbitrary scripts as root. Mass scanning began within 72 hours of disclosure.