← Back to Vulnerability Reports

Vulnerability Priority Report – Week 2 of June 2026

📅 June 8 – 14🟢 Live · updated 2026-06-1422 CVEs tracked this week

Analyst Guidance

Organizations should prioritize patching these vulnerabilities immediately — several are actively exploited in the wild and confirmed in CISA's KEV catalog, most urgently Oracle PeopleSoft (CVE-2026-35273) and Ivanti Sentry (CVE-2026-10520), alongside a critical unauthenticated remote code execution flaw in Splunk Enterprise (CVE-2026-20253). Patch internet-facing and identity systems first.

CVE Details & Remediation

How to read this report
Verified facts — NVD & CISA KEV Partially verified — awaiting NVD enrichment AI analysis — synthesis, verify before acting
Actionable · Verified facts
NVD-published · CISA KEV cross-checked

🛡️CVE-2026-10520 – Ivanti Sentry ✓ NVD

CVSS10 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild In CISA KEV
EPSS43% · P98
ActionPatch immediately

Remediation Steps

  1. Obtain the latest security patch for Ivanti Sentry from Ivanti
  2. Apply the OS command injection fix immediately to all Ivanti Sentry instances
  3. Review system logs and command execution histories for signs of compromise
  4. Restrict administrative access and validate user accounts for unauthorized modifications

References:

🛡️CVE-2026-35273 – Oracle PeopleSoft Enterprise PeopleTools ✓ NVD

CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild In CISA KEV
EPSS22% · P96
ActionPatch immediately

Remediation Steps

  1. Review CISA's Known Exploited Vulnerabilities catalog entry for CVE-2026-35273
  2. Obtain and apply the latest security patch from Oracle
  3. Prioritize patching Oracle PeopleSoft instances accessible over the network
  4. Monitor logs for evidence of exploitation attempts

References:

🛡️CVE-2026-45247 – Mirasvit Full Page Cache Warmer ✓ NVD

CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild In CISA KEV
EPSS6% · P91
ActionPatch immediately

Remediation Steps

  1. Consult CISA Known Exploited Vulnerabilities catalog entry for full product and version details
  2. Apply vendor security patch
  3. Verify patch deployment across affected systems
  4. Review security logs for evidence of exploitation

References:

🛡️CVE-2026-48172 – LiteSpeed CPanel Plugin ✓ NVD

CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild In CISA KEV
EPSS8% · P92
ActionPatch immediately

Remediation Steps

  1. Apply the latest security patch from LiteSpeed for the cPanel Plugin immediately
  2. Verify that only authorized cPanel users have access to affected systems
  3. Review system logs for evidence of exploitation or unauthorized script execution
  4. Restrict cPanel administrative access to trusted networks where feasible

References:

🛡️CVE-2026-9082 – Drupal Core ✓ NVD

CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild In CISA KEV
EPSS10% · P93
ActionPatch immediately

Remediation Steps

  1. Update all supported Drupal Core versions to the latest patched release immediately
  2. Review database query logs for evidence of SQL injection attempts
  3. Ensure database user accounts are restricted to minimum required privileges
  4. Monitor for malicious activity on systems running affected Drupal versions

References:

🛡️CVE-2026-50751 – Check Point Security Gateway ✓ NVD

CVSS9.3 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild In CISA KEV
EPSS12% · P94
ActionPatch immediately
AffectedTechnology Finance Government Defense

Remediation Steps

  1. Apply the vendor security update for Check Point Remote Access VPN / Mobile Access as a priority.
  2. Restrict network exposure of the affected service to trusted sources until patched.
  3. Review logs and detections for indicators of exploitation.
  4. Confirm fixed versions against the official vendor advisory before deploying.

References:

🛡️CVE-2026-0257 – Palo Alto Networks PAN-OS ✓ NVD

CVSS9.1 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild In CISA KEV
EPSS59% · P98
ActionPatch immediately
AffectedGovernment Technology Finance Transportation

Remediation Steps

  1. Apply the vendor security update for Paloaltonetworks Pan-Os as a priority.
  2. Restrict network exposure of the affected service to trusted sources until patched.
  3. Review logs and detections for indicators of exploitation.
  4. Confirm fixed versions against the official vendor advisory before deploying.

References:

🛡️CVE-2025-8088 – RARLAB WinRAR ✓ NVD

CVSS8.8 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild In CISA KEV
EPSS12% · P94
ActionPatch immediately
AffectedTechnology Government Defense

Remediation Steps

  1. Apply the vendor security update for Rarlab Winrar as a priority.
  2. Restrict network exposure of the affected service to trusted sources until patched.
  3. Review logs and detections for indicators of exploitation.
  4. Confirm fixed versions against the official vendor advisory before deploying.

References:

🛡️CVE-2026-42271 – BerriAI LiteLLM ✓ NVD

CVSS8.8 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild In CISA KEV
EPSS61% · P98
ActionPatch immediately

Remediation Steps

  1. Check CISA's Known Exploited Vulnerabilities catalog for product-specific guidance
  2. Contact vendor for available security patches
  3. Apply patch or implement recommended mitigations from vendor advisory
  4. Verify patch installation and monitor for indicators of active exploitation

References:

🛡️CVE-2026-11645 – Google Chromium V8 ✓ NVD

CVSS8.8 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild In CISA KEV
EPSS5% · P90
ActionPatch immediately

Remediation Steps

  1. Update Google Chrome to version 149.0.7827.103 or later
  2. Enable automatic updates to receive future security patches promptly
  3. Check for and remove any suspicious browser extensions
  4. Clear browser cache and temporary files after patching

References:

🛡️CVE-2025-48595 – Android Framework ✓ NVD

CVSS8.4 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild In CISA KEV
EPSS1% · P68
ActionPatch immediately
AffectedTechnology Government

Remediation Steps

  1. Apply the vendor security update for Google Android as a priority.
  2. Restrict network exposure of the affected service to trusted sources until patched.
  3. Review logs and detections for indicators of exploitation.
  4. Confirm fixed versions against the official vendor advisory before deploying.

References:

🛡️CVE-2026-20245 – Cisco Catalyst SD-WAN Manager ✓ NVD

CVSS7.8 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild In CISA KEV
EPSS<1% · P58
ActionPatch immediately
AffectedTechnology Defense

Remediation Steps

  1. Apply the vendor security update for Cisco as a priority.
  2. Restrict network exposure of the affected service to trusted sources until patched.
  3. Review logs and detections for indicators of exploitation.
  4. Confirm fixed versions against the official vendor advisory before deploying.

References:

🛡️CVE-2022-0492 – Linux Kernel ✓ NVD

CVSS7.8 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild In CISA KEV
EPSS27% · P97
ActionPatch immediately
AffectedTechnology Government Energy

Remediation Steps

  1. Identify Linux systems running vulnerable kernel versions
  2. Apply the latest stable kernel update from your distribution's repository
  3. Reboot systems to activate patched kernel
  4. Verify kernel version post-reboot using 'uname -r'
  5. Prioritize kernel patching for systems exposed to untrusted local users or containers

References:

🛡️CVE-2026-28318 – SolarWinds Serv-U ✓ NVD

CVSS7.5 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild In CISA KEV
EPSS6% · P91
ActionPatch immediately

Remediation Steps

  1. Check CISA's Known Exploited Vulnerabilities catalog for product-specific guidance
  2. Contact vendor for available security patches
  3. Apply patch or implement recommended mitigations from vendor advisory
  4. Verify patch installation and monitor for indicators of active exploitation

References:

🛡️CVE-2024-21182 – Oracle WebLogic Server ✓ NVD

CVSS7.5 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild In CISA KEV
EPSS90% · P100
ActionPatch immediately
AffectedTechnology Government

Remediation Steps

  1. Apply the vendor security update for Oracle Weblogic Server as a priority.
  2. Restrict network exposure of the affected service to trusted sources until patched.
  3. Review logs and detections for indicators of exploitation.
  4. Confirm fixed versions against the official vendor advisory before deploying.

References:

🛡️CVE-2026-3300 – WordPress Everest Forms Pro ✓ NVD

CVSS9.8 NVD 3.1
Triage statusNo Known Exploit
ExploitationNo exploitation reported
EPSS35% · P97
ActionPatch within 48 hours
AffectedTechnology Government

Remediation Steps

  1. Apply the vendor security update for WordPress Everest Forms Pro as a priority.
  2. Restrict network exposure of the affected service to trusted sources until patched.
  3. Review logs and detections for indicators of exploitation.
  4. Confirm fixed versions against the official vendor advisory before deploying.

References:

🛡️CVE-2026-5027 – Langflow ✓ NVD

CVSS8.8 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild
EPSS4% · P89
ActionPatch within 48 hours
AffectedTechnology Defense

Remediation Steps

  1. Apply the vendor security update for Langflow as a priority.
  2. Restrict network exposure of the affected service to trusted sources until patched.
  3. Review logs and detections for indicators of exploitation.
  4. Confirm fixed versions against the official vendor advisory before deploying.

References:

🛡️CVE-2026-7473 – Arista Extensible Operating System ✓ NVD

CVSS5.8 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild In CISA KEV
EPSS27% · P97
ActionPatch immediately

Remediation Steps

  1. Check Arista's security advisory for CVE-2026-7473 and available patches
  2. Test patches in a non-production environment before deployment
  3. Plan maintenance windows to apply fixes to Arista network devices
  4. Validate network device functionality post-patch

References:

🛡️CVE-2026-20253 – Splunk Enterprise ✓ NVD

CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild In CISA KEV
EPSS<1% · P21
ActionPatch within 48 hours

Remediation Steps

  1. Upgrade Splunk Enterprise to version 10.2.4 or 10.0.7 or later
  2. If immediate upgrade is not possible, restrict network access to Splunk Enterprise instances to trusted internal networks only
  3. Review authentication and authorization logs for suspicious unauthenticated file operations
  4. Apply vendor security updates as soon as they become available

References:

🛡️CVE-2026-25089 – Fortinet FortiSandbox, FortiSandbox Cloud, FortiSandbox PaaS ✓ NVD

CVSS9.8 NVD 3.1
Triage statusNo Known Exploit
ExploitationNo exploitation reported
EPSS1% · P76
ActionPatch within 48 hours

Remediation Steps

  1. Apply Fortinet security patch for the command injection vulnerability in FortiSandbox WEB UI
  2. Review and restrict administrative access to FortiSandbox deployments
  3. Validate that command injection attempts are blocked or logged
  4. Monitor FortiSandbox logs for exploitation attempts

References:

🛡️CVE-2026-23111 – Linux Kernel ✓ NVD

CVSS7.8 NVD 3.1
Triage statusNo Known Exploit
ExploitationNo exploitation reported
EPSS<1% · P2
ActionPatch this week
AffectedTechnology Finance Government Defense

Remediation Steps

  1. Apply the vendor security update for Linux Kernel as a priority.
  2. Restrict network exposure of the affected service to trusted sources until patched.
  3. Review logs and detections for indicators of exploitation.
  4. Confirm fixed versions against the official vendor advisory before deploying.

References:

Actionable · Partially verified
CVE in source articles · NVD enrichment pending

CVE-2026-44963 – Veeam Backup & Replication pending NVD

CVSSawaiting NVD
Triage statusUnder Review
ExploitationNo exploitation reported
EPSS1% · P70
ActionPatch within 48 hours

Remediation Steps

  1. Apply the latest security patch from Veeam for Backup & Replication
  2. Restrict Backup Server access to authenticated domain users only
  3. Monitor backup server logs for suspicious authentication and code execution activity
  4. Isolate affected backup servers from untrusted network segments until patched

References:

These CVEs are real (IDs appear in source articles) but NVD has not yet finished enrichment. Canonical vendor/product/CVSS data will appear here automatically once NVD catches up — we re-check daily.
🤖 This vulnerability report was compiled by defend.network using AI-powered analysis of vulnerability databases, vendor advisories, and threat intelligence feeds. Always verify remediation steps through official vendor channels before implementing changes in production environments.

Get Vulnerability Priority Updates

Subscribe free and stay on top of critical patches.