Security news, decoded.
73 stories in the last 7 days, naming 204 CVEs; 60 of those CVEs are in CISA KEV.
The wire
Tuesday, Jun 1610 stories
- SecurityWeekCisco Patches Another SD-WAN Zero-Day Exploited in AttacksReported exploitedCatalyst SD-WAN Manager
- The Hacker NewsCisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw
Cisco has released security updates for CVE-2026-20262, a medium-severity vulnerability in the web UI of Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) that is being actively exploited in the wild. The issue can let an authenticated remote attacker abuse a file upload path-handling weakness to create or overwrite files on the device’s filesystem, which may be leveraged toward higher privileges depending on attacker access. The fix is available across multiple Cisco Catalyst SD-WAN releases, including Cisco Catalyst SD-WAN Release 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, and 26.1.1.2, covering Cisco Catalyst SD-WAN Manager On-Prem, Cisco SD-WAN Cloud-Pro, Cisco SD-WAN Cloud (Cisco Managed), and Cisco SD-WAN for Government (FedRAMP).
Reported exploitedCatalyst SD-WAN Manager - The Hacker NewsCISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege EscalationReported exploitedLiteSpeed cPanel Plugin
- Daily CyberSecurity (securityonline.info)Three Tornado Security Vulnerabilities Patched in Version 6.5.6
Tornado maintainers have released version 6.5.6 to patch three security issues in the Python web framework, including CVE-2026-49853, CVE-2026-49855, and CVE-2026-49854. CVE-2026-49853 (7.7) can leak Authorization headers when SimpleAsyncHTTPClient follows redirects to a different origin, potentially exposing credentials across sites. CVE-2026-49855 (7.5) addresses a gzip bomb that could exhaust memory, while CVE-2026-49854 (5.3) fixes an out-of-bounds read in Tornado’s optional native extension that could reveal small amounts of uninitialized memory. Upgrading to Tornado 6.5.6 is the recommended mitigation, especially to address the credential-leak risk.
PatchTornado (Python web framework) - Daily CyberSecurity (securityonline.info)
- Daily CyberSecurity (securityonline.info)Haskell TLS Vulnerability Lets Attackers Forge Trusted Certificates (CVE-2026-9648)
A critical issue in the Haskell library crypton-x509-validation (CVE-2026-9648, CVSS 9.1) allows TLS clients to accept forged certificates because the library does not enforce X.509 NameConstraints as required by RFC 5280. This matters because it can let attackers extend trust beyond the permitted scope of a name-constrained CA, potentially enabling credential/session interception in real-world deployments, especially delegated PKI used by financial institutions. CERT/CC reports that upgrading to crypton-x509-validation version 1.9.1 is the recommended mitigation.
Patchcrypton-x509-validation - Daily CyberSecurity (securityonline.info)Naxclow IoT Vulnerabilities: 7 Flaws Let Attackers Hijack Doorbells and CamerasAdvisorySmart Doorbell X3
- Daily CyberSecurity (securityonline.info)
- Daily CyberSecurity (securityonline.info)Thousands of phpBB Forums Exposed by Critical Authentication Bypass
phpBB has disclosed a critical authentication bypass, tracked as CVE-2026-48611, that can allow an unauthenticated attacker to log in as arbitrary users (including administrators) by abusing phpBB’s OAuth-related session handling. The flaw affects phpBB versions up to and including 3.3.16, and the 4.0.0 alpha branch, meaning many installations are exposed by default. This is a severe risk because it enables account takeover via a crafted request, and administrators should update to 3.3.17 (or apply the official mitigations/workarounds) as an urgent priority.
PatchphpBB 3.x - Daily CyberSecurity (securityonline.info)LiteSpeed cPanel Privilege Escalation Flaw Exploited in the Wild (CVE-2026-54420)
CVE-2026-54420 is a privilege escalation issue in the LiteSpeed cPanel plugin (before version 2.4.8) that is reportedly under active attack, allowing a low-privileged tenant on shared hosting to escape isolation and obtain full root access. The flaw involves improper handling of user-controlled symlinks when the server runs CloudLinux/CageFS, which matters because compromising one account can put all sites on the same host at risk. LiteSpeed has remediated the problem in cPanel plugin v2.4.8 (bundled with WHM Plugin v5.3.2.1), so administrators should patch immediately and investigate logs for suspicious activity.
Reported exploitedLiteSpeed cPanel Plugin
Monday, Jun 1521 stories
- BleepingComputer
- Dark ReadingHTTP/2 Bomb Attacks Put Telcos, Healthcare Orgs at RiskPoC publicnginx
- Dark ReadingCopilot 'SearchLeak' Attack Allows 1-Click Data Theft
Researchers describe a new Microsoft Copilot attack dubbed “SearchLeak” that can let an adversary exfiltrate user-accessible Microsoft 365 data, including emails, meeting notes, OneDrive files, and SharePoint documents, using a crafted Copilot Search link with no extra victim action. Varonis Threat Labs says the multi-stage issue relies on a lesser-known parameter-to-prompt Injection (P2P) pattern and can bypass protections by embedding attacker-controlled content in ways that trigger AI behavior before sanitization. Microsoft has patched the vulnerability as CVE-2026-42824, underscoring how prompt-injection weaknesses in LLM-based enterprise assistants can turn internal data access into an attacker-controlled output channel.
PoC publicMicrosoft 365 Copilot Enterprise Search - BleepingComputerCisco fixes SD-WAN vManage flaw exploited in zero-day attacksReported exploitedCisco Catalyst SD-WAN Manager
- The Hacker NewsLiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers
Researchers at Obsidian Security report a multi-step vulnerability chain in LiteLLM that can allow a default low-privilege account to escalate to full proxy admin and achieve code execution. The affected issues are tracked as CVE-2026-47101, CVE-2026-47102, and CVE-2026-40217; together they can bypass authorization, elevate privileges, and escape the Custom Code Guardrail’s sandbox. Because LiteLLM sits in the middle of AI requests, a takeover can expose provider keys and sensitive traffic and can also let attackers tamper with prompts/responses processed by downstream agents. BerriAI’s fix is included starting with LiteLLM v1.83.14-stable—upgrade to that release or later to mitigate.
PoC publicLiteLLM - Daily CyberSecurity (securityonline.info)Cisco SD-WAN Vulnerability Exploited in the Wild: Patch CVE-2026-20262 NowReported exploitedCisco Catalyst SD-WAN Manager
- The Hacker NewsOne-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes
Researchers at Varonis Threat Labs describe a chained vulnerability in Microsoft 365 Copilot Enterprise Search that could let attackers steal emails, calendar information, and indexed files after a user clicks a seemingly legitimate microsoft.com link. The issue is tracked as CVE-2026-42824 and matters because it can also expose time-sensitive authentication material such as one-time codes and MFA codes, potentially enabling account takeover. Microsoft has issued a critical mitigation on its backend, but tenant admins still need to monitor for suspicious Copilot Search URLs and related outbound requests.
PoC publicMicrosoft 365 Copilot Enterprise Search - The Hacker News⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and MoreReported exploitedChrome (V8)
- Check Point Research15th June – Threat Intelligence ReportReported exploitedOracle PeopleSoft
- BleepingComputerNew attack turned Microsoft 365 Copilot into 1-click data theft tool
A newly detailed attack chain, dubbed SearchLeak, shows how Microsoft 365 Copilot Enterprise can be turned into a one-click data theft mechanism using a specially crafted URL. The technique targets sensitive content from a victim’s mailbox, OneDrive, or SharePoint by abusing Microsoft 365 Copilot Search, ultimately exfiltrating data via browser-driven and Bing-facilitated requests. Microsoft addressed the issue with fixes for CVE-2026-42824, rated critical, which is important because exploiting the weaknesses does not require additional user actions beyond clicking the link.
PoC publicMicrosoft 365 Copilot Enterprise Search - The Hacker NewsPopular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on SitesReported exploitedPushEngage
- Daily CyberSecurity (securityonline.info)Jenkins RCE Vulnerability CVE-2026-53435 Now Under Active Exploitation
Attackers are actively exploiting a critical remote code execution flaw in Jenkins, tracked as CVE-2026-53435. The issue allows adversaries to run arbitrary code on Jenkins controllers, including impersonating users and reaching the Script Console to execute commands or access sensitive files. Jenkins users on Jenkins 2.567 and earlier, as well as LTS 2.555.2 and earlier, should patch immediately; the same advisory also addresses open-redirect issues CVE-2026-53436 and CVE-2026-53437, though they are less severe.
Reported exploitedJenkins (controllers) - The Hacker NewsPalo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw
Palo Alto Networks says it has detected active exploitation of a PAN-OS flaw used to gain unauthorized access to GlobalProtect portals, with attack activity beginning May 17, 2026. The issue is tracked as CVE-2026-0257 (CVSS 7.8), an authentication bypass affecting GlobalProtect portal and gateway components that could let attackers establish VPN connections and evade security checks. The U.S. CISA added CVE-2026-0257 to its Known Exploited Vulnerabilities catalog, underscoring the need for urgent mitigation.
Reported exploitedPAN-OS GlobalProtect (portal and gateway) - Daily CyberSecurity (securityonline.info)
- Daily CyberSecurity (securityonline.info)FreePBX RCE Vulnerabilities Threaten Telecom ServersPatchFreePBX Superfecta module
- Daily CyberSecurity (securityonline.info)
- Daily CyberSecurity (securityonline.info)Critical Wazuh CVSS 10 Vulnerability Details and Proof-of-Concept ReleasedPoC publicWazuh 5.0 inventory pipeline (wazuh-manager)
- Daily CyberSecurity (securityonline.info)Old WinRAR Flaw Still Fuels Attacks on Ukraine in 2026Reported exploitedWinRAR
- Daily CyberSecurity (securityonline.info)Weekly Threat Intelligence: June 8 to June 14, 2026Reported exploitedIvanti Sentry
- Daily CyberSecurity (securityonline.info)Vulnerable UEFI Shim Bootloaders Risk Broad Secure Boot BypassAdvisoryUEFI shim bootloaders
- Daily CyberSecurity (securityonline.info)CodeIgniter Vulnerability Enables Arbitrary Code Execution (CVSS 9.8)PatchCodeIgniter 4.7.3
Saturday, Jun 134 stories
- The Hacker NewsCritical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication
Splunk released security updates for a critical issue in Splunk Enterprise that allows network-reachable attackers to perform unauthenticated PostgreSQL sidecar file operations, potentially escalating to remote code execution. The vulnerability is tracked as CVE-2026-20253 (CVSS 9.8) and affects Splunk Enterprise versions below 10.2.4 and 10.0.7, with fixes in 10.0.7 and 10.2.4 (Splunk Enterprise 10.4 is not affected). Splunk Cloud is reported as not impacted because it does not use PostgreSQL sidecars. Apply the vendor patches promptly to reduce the risk of exploitation.
PatchSplunk Enterprise 10.0.7 - Daily CyberSecurity (securityonline.info)SimpleHelp Authentication Bypass Exploited to Hijack Remote Endpoints
Researchers report a maximum-severity authentication bypass in SimpleHelp, tracked as CVE-2026-48558 (CVSS 10), that enables unauthenticated attackers to forge identity tokens and obtain administrative control. The flaw is tied to the app’s OIDC single sign-on handling, where submitted tokens can be accepted without proper cryptographic signature verification, also undermining MFA protections. This matters because compromised instances can execute scripts and pivot into managed endpoints, so organizations should review internet-exposed remote support systems and patch or harden OIDC configurations promptly.
Reported exploitedSimpleHelp - Daily CyberSecurity (securityonline.info)
- Daily CyberSecurity (securityonline.info)Important Apache CXF Vulnerabilities Demand Immediate Action
Apache CXF discloses multiple security issues affecting the JCA integration, WS JSON request filtering, and XML parsing behavior, including CVE-2026-50633 and CVE-2026-50634, plus CVE-2026-50628 and CVE-2026-49875. These problems matter because they could enable scenarios like unauthorized code execution, bypassed validation logic, and XML External Entity exposure when systems handle attacker-controlled inputs. Apache recommends upgrading to versions 4.2.2 or 4.1.7 to address the reported issues.
PatchApache CXF
Friday, Jun 125 stories
- watchTowr LabsWhy Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE)
Splunk Enterprise has been impacted by CVE-2026-20253, where the “PostgreSQL Sidecar Service Endpoint” does not properly enforce authentication controls and can be invoked in a way that leads to arbitrary file creation and truncation. The issue matters because it can be chained to achieve pre-auth RCE in certain deployments (notably Splunk Enterprise on AWS), despite the endpoint being intended to be reachable only locally. If you run affected versions of Splunk Enterprise, prioritize reviewing the vendor advisory and applying the recommended mitigations for CVE-2026-20253.
ResearchSplunk Enterprise - Dark ReadingShinyHunters Uses Oracle Zero-Day to Rampage Higher EdReported exploitedOracle PeopleSoft
- Ars Technica (Security)PeopleSoft 0-day affecting hundreds of organizations steals gigabytes of dataReported exploitedPeopleSoft Enterprise PeopleTools
- The Hacker NewsChina-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade
Sygnia attributes attacks by a China-nexus group tracked as Velvet Ant to backdooring Linux authentication paths by altering PAM and OpenSSH login components that control who can sign in. The malware appears to have persisted from at least 2016 by replacing trusted login binaries—sometimes to capture real usernames and passwords and sometimes to execute hidden behavior—so standard recovery steps like password resets and session termination may fail. The same actor has previously targeted other products, including F5 BIG-IP and Cisco NX-OS, and Cisco NX-OS exploitation tied to CVE-2024-20399 (with admin access required) was reported as part of its persistence activity, underscoring why integrity checks for critical authentication software matter.
ResearchLinux PAM - SecurityWeekIn Other News: Google Security Layoffs, AudiA6 Takedown, $400 Million Coupang Fine
CISA added CVE-2026-42271, a command injection issue affecting BerriAI LiteLLM (an AI gateway), to its Known Exploited Vulnerabilities catalog after evidence of active exploitation, making urgent patching important. Separately, South Korea’s PIPC issued a record $400 million penalty to Coupang after security and data-handling failures exposed personal information of more than 30 million customers. In a major enforcement action, an international operation dismantled AudiA6, disrupting a crypto laundering pipeline tied to ransomware financing and seizing related infrastructure and forums.
Roundup