cbcvebase.
← Exploited This Week

Exploited This Week — Jun 15–Jun 22, 2026

4 KEV · 20 newly weaponized · 8 EPSS surges

Patch now — added to CISA KEV

CVE-2026-20253
Splunk Enterprise Missing Authentication for Critical Function Vulnerability
CISA KEV (added 2026-06-18, due 2026-06-21) · CVSS 9.8 CRITICAL · EPSS 0.10 (95th pct)

In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists because the PostgreSQL…

Nuclei templateblogs_bleepingcomputer, blogs_hackernews, vuldb, vulncheck
CVE-2026-48907
Widget Factory Joomla Content Editor Improper Access Control Vulnerability
CISA KEV (added 2026-06-16, due 2026-06-19) · CVSS 10 CRITICAL · EPSS 0.07 (93th pct)

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.

Nuclei templateblogs_bleepingcomputer, blogs_hackernews, vuldb, vulncheck
CVE-2026-20262
Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability
CISA KEV (added 2026-06-15, due 2026-06-29) · CVSS 6.5 MEDIUM · EPSS 0.01 (63th pct)

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This vulnerability…

blogs_bleepingcomputer, blogs_hackernews, vuldb, vulncheck
CVE-2026-54420
LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability
CISA KEV (added 2026-06-15, due 2026-06-18) · CVSS 8.5 HIGH · EPSS 0.01 (46th pct)

LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the…

blogs_bleepingcomputer, blogs_hackernews, vuldb, vulncheck

Newly weaponized — exploit code appeared

CVE-2026-50751
Check Point Security Gateway Improper Authentication Vulnerability
CISA KEV (added 2026-06-08, due 2026-06-11) · 🦠 ransomware · CVSS 9.3 CRITICAL · EPSS 0.41 (98th pct)

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without…

Nuclei templateblogs_bleepingcomputer, blogs_checkpoint, blogs_hackernews, blogs_rapid7 +2
CVE-2026-25555
OpenBullet2 through version 0.3.2 contains an authentication bypass vulnerability in the API key authentication…
CVSS 9.8 CRITICAL · EPSS 0.03 (84th pct)

OpenBullet2 through version 0.3.2 contains an authentication bypass vulnerability in the API key authentication middleware that allows unauthenticated attackers to gain admin access by supplying an empty X-Api-Key header value. Attackers…

Nuclei templatevuldb
CVE-2026-34415
Xerte Online Toolkits Arbitrary File Upload - Unauthenticated Media Upload
CVSS 9.8 CRITICAL · EPSS 0.02 (79th pct)

Xerte Online Toolkits versions 3.15 and earlier contain an incomplete input validation vulnerability in the elFinder connector endpoint that fails to block PHP-executable extensions .php4 due to an incorrect regex pattern. Unauthenticated…

Metasploit moduleblogs_rapid7, vuldb
CVE-2026-27760
OpenCATS prior to commit 3002a29 contains a PHP code injection vulnerability in the installer AJAX endpoint that…
CVSS 8.1 HIGH · EPSS 0.02 (75th pct)

OpenCATS prior to commit 3002a29 contains a PHP code injection vulnerability in the installer AJAX endpoint that allows unauthenticated attackers to execute arbitrary code by injecting PHP statements into the databaseConnectivity action…

Nuclei templatevuldb, vulncheck
CVE-2026-0826
HP Poly Voice Unauthenticated Remote Code Execution
CVSS 9.2 CRITICAL · EPSS 0.01 (67th pct)

In certain scenarios when the admin has enabled Interactive Connectivity Establishment (ICE), a buffer overflow could enable remote code execution on Poly Voice products on the Linux platform.

Metasploit moduleblogs_hackernews, blogs_rapid7
CVE-2026-10795
updraftplus updraftplus Improper Verification of Cryptographic Signature
CVSS 8.1 HIGH · EPSS 0.01 (66th pct)

The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.26.4 via the UpdraftPlus_Remote_Communications_V2::wp_loaded function. This is due to…

Nuclei templateblogs_hackernews, vuldb, vulncheck
CVE-2026-27826
MCP Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url / X-Atlassian-Confluence-Url headers
CVSS 8.2 HIGH · EPSS 0.01 (64th pct)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to version 0.17.0, an unauthenticated attacker who can reach the mcp-atlassian HTTP endpoint can force the server process to make…

Nuclei templateblogs_hackernews, blogs_wiz
CVE-2026-50230
Lyrion Music Server 9.2.0 contains an unauthenticated reflected cross-site scripting vulnerability in the server.log…
CVSS 6.1 MEDIUM · EPSS 0.00 (24th pct)

Lyrion Music Server 9.2.0 contains an unauthenticated reflected cross-site scripting vulnerability in the server.log endpoint that allows attackers to inject arbitrary HTML and JavaScript code through the search parameter. Attackers can…

Nuclei templatevuldb
CVE-2026-35273
Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability
CISA KEV (added 2026-06-12, due 2026-06-15) · 🦠 ransomware · CVSS 9.8 CRITICAL · EPSS 0.08 (94th pct)

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows…

blogs_bleepingcomputer, blogs_checkpoint, blogs_hackernews, blogs_mandiant +3
CVE-2026-34414
Xerte Online Toolkits Arbitrary File Upload - Unauthenticated Media Upload
CVSS 7.1 HIGH · EPSS 0.02 (81th pct)

Xerte Online Toolkits versions 3.15 and earlier contain a relative path traversal vulnerability in the elFinder connector endpoint at /editor/elfinder/php/connector.php where the name parameter in rename commands is not sanitized for path…

Metasploit moduleblogs_rapid7, vuldb

+9 more lower-signal CVEs gained public exploit code this week.

EPSS surges — exploitation risk jumped

CVE-2024-29826
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated…
CVSS 8.8 HIGH · EPSS 1.00 (100th pct) · ↑ EPSS 0.02→1.00 (+0.97) over 7d

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.

🔧 no public PoC or detection rule linked yet — detection gap
CVE-2024-29825
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated…
CVSS 8.8 HIGH · EPSS 1.00 (100th pct) · ↑ EPSS 0.02→1.00 (+0.97) over 7d

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.

🔧 no public PoC or detection rule linked yet — detection gap
CVE-2024-29823
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated…
CVSS 8.8 HIGH · EPSS 1.00 (100th pct) · ↑ EPSS 0.02→1.00 (+0.97) over 7d

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.

🔧 no public PoC or detection rule linked yet — detection gap
CVE-2012-1446
The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, AVEngine…
CVSS 4.3 MEDIUM · EPSS 1.00 (100th pct) · ↑ EPSS 0.03→1.00 (+0.97) over 7d

The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Norman Antivirus 6.06.12, eSafe 7.0.17.0, Kaspersky Anti-Virus…

🔧 no public PoC or detection rule linked yet — detection gap
CVE-2020-11022
Drupal vulnerabilities
CVSS 6.1 MEDIUM · EPSS 0.99 (100th pct) · ↑ EPSS 0.02→0.99 (+0.97) over 7d

In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem…

ExploitDB PoCblogs_huntress, blogs_tenable, vuldb, vulncheck
CVE-2012-1442
The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee…
CVSS 4.3 MEDIUM · EPSS 0.99 (100th pct) · ↑ EPSS 0.03→0.99 (+0.96) over 7d

The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, eSafe 7.0.17.0, Kaspersky Anti-Virus 7.0.0.125, F-Secure Anti-Virus 9.0.16160.0…

🔧 no public PoC or detection rule linked yet — detection gap
CVE-2012-1430
The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, McAfee…
CVSS 4.3 MEDIUM · EPSS 0.96 (100th pct) · ↑ EPSS 0.01→0.96 (+0.96) over 7d

The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, nProtect Anti-Virus…

🔧 no public PoC or detection rule linked yet — detection gap
CVE-2012-1431
The ELF file parser in Bitdefender 7.2, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Prot…
CVSS 4.3 MEDIUM · EPSS 0.96 (100th pct) · ↑ EPSS 0.01→0.96 (+0.96) over 7d

The ELF file parser in Bitdefender 7.2, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, F-Secure Anti-Virus 9.0.16160.0, McAfee Gateway (formerly Webwasher) 2010.1C, nProtect Anti-Virus…

🔧 no public PoC or detection rule linked yet — detection gap

Get this every Monday

Free weekly digest for blue teams — what got weaponized, with detection coverage.