← Back to Vulnerability Reports

Vulnerability Priority Report – Week 5 of June 2026

📅 June 29 – July 5🟢 Live · updated 2026-07-0531 CVEs tracked this week

Analyst Guidance

This week's verified CVE activity is light, with only two explicitly identified vulnerabilities in the source material. The most urgent priority is CVE-2026-45659, which CISA reports as actively exploited in the wild and has added to its Known Exploited Vulnerabilities Catalog. CVE-2026-46242 affects Linux and Android systems with privilege escalation risk. Beyond discrete CVEs, security teams should monitor emerging disclosure patterns: runZero disclosed seven vulnerabilities in FatFs (a filesystem library in millions of embedded devices), and FortiBleed actors are consolidating access across Fortinet firewalls while collaborating with ransomware groups—indicating a shift toward coordinated supply-chain and infrastructure targeting.

CVE Details & Remediation

How to read this report
Verified facts — NVD & CISA KEV Partially verified — awaiting NVD enrichment AI analysis — synthesis, verify before acting
Actionable · Verified facts
NVD-published · CISA KEV cross-checked

🛡️CVE-2026-48558 – Simple-Help Simplehelp ✓ NVD

CVSS10 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild In CISA KEV
EPSS1% · P63
ActionPatch immediately
AffectedTechnology

Remediation Steps

  1. Apply the vendor security update for SimpleHelp as a priority.
  2. Restrict network exposure of the affected service to trusted sources until patched.
  3. Review logs and detections for indicators of exploitation.
  4. Confirm fixed versions against the official vendor advisory before deploying.

References:

🛡️CVE-2026-10520 – Ivanti Sentry ✓ NVD

CVSS10 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild In CISA KEV
EPSS99% · P100
ActionPatch immediately

🛡️CVE-2026-33017 – Langflow ✓ NVD

CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild In CISA KEV
EPSS98% · P100
ActionPatch immediately
AffectedTechnology

Remediation Steps

  1. Apply the vendor security update for Langflow as a priority.
  2. Restrict network exposure of the affected service to trusted sources until patched.
  3. Review logs and detections for indicators of exploitation.
  4. Confirm fixed versions against the official vendor advisory before deploying.

References:

🛡️CVE-2026-12569 – PTC Windchill And FlexPLM ✓ NVD

CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild In CISA KEV
EPSS1% · P62
ActionPatch immediately

Remediation Steps

  1. Refer to CISA Known Exploited Vulnerabilities catalog for vendor-specific remediation guidance
  2. Apply patches provided by the affected vendor
  3. Monitor systems for signs of compromise
  4. Verify that systems are no longer vulnerable before returning to production

References:

🛡️CVE-2025-67038 – Lantronix EDS5000 ✓ NVD

CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild In CISA KEV
EPSS1% · P63
ActionPatch immediately

Remediation Steps

  1. Apply vendor patches immediately per Lantronix security advisory
  2. Isolate affected Lantronix EDS5000 devices from untrusted network segments
  3. Monitor for signs of unauthorized access or code execution
  4. Implement network access controls to restrict inbound traffic to EDS5000 management interfaces

References:

🛡️CVE-2026-20253 – Splunk Enterprise ✓ NVD

CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild In CISA KEV
EPSS88% · P100
ActionPatch immediately

Remediation Steps

  1. Apply the vendor patch for Splunk Enterprise Missing Authentication issue immediately
  2. Verify patch installation across all Splunk Enterprise instances
  3. Monitor Splunk logs for any evidence of unauthorized access or exploitation attempts
  4. Restrict network access to Splunk management interfaces to trusted networks only

References:

🛡️CVE-2026-35273 – Oracle PeopleSoft Enterprise PeopleTools ✓ NVD

CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild In CISA KEV
EPSS92% · P100
ActionPatch immediately

Remediation Steps

  1. Apply Oracle PeopleSoft Enterprise security patch
  2. Review Oracle security advisories for affected version guidance
  3. Prioritize patching systems accessible from external networks

References:

🛡️CVE-2026-45247 – Mirasvit Full Page Cache Warmer ✓ NVD

CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild In CISA KEV
EPSS28% · P98
ActionPatch immediately

Remediation Steps

  1. Consult CISA Known Exploited Vulnerabilities catalog entry for full product and version details
  2. Apply vendor security patch
  3. Verify patch deployment across affected systems
  4. Review security logs for evidence of exploitation

References:

🛡️CVE-2026-48907 – Widget Factory Joomla Content Editor ✓ NVD

CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild In CISA KEV
EPSS80% · P100
ActionPatch immediately

Remediation Steps

  1. Apply security patch from Widget Factory/Joomla vendor immediately
  2. Disable the JCE plugin if patch is not immediately available
  3. Review access logs for evidence of exploitation attempts

References:

🛡️CVE-2026-50751 – Check Point Security Gateway ✓ NVD

CVSS9.3 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild In CISA KEV
EPSS70% · P99
ActionPatch immediately
AffectedTechnology Finance Government Defense

Remediation Steps

  1. Apply the vendor security update for Check Point Remote Access VPN / Mobile Access as a priority.
  2. Restrict network exposure of the affected service to trusted sources until patched.
  3. Review logs and detections for indicators of exploitation.
  4. Confirm fixed versions against the official vendor advisory before deploying.

References:

🛡️CVE-2026-50548 – Anysphere Cursor ✓ NVD

CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild
EPSS1% · P46
ActionPatch within 48 hours

Remediation Steps

  1. Update Cursor to the latest patched version
  2. Disable or restrict execution of untrusted code snippets and prompts
  3. Review Cursor's sandbox configuration and security settings
  4. Educate users on risks of prompt injection attacks

References:

🛡️CVE-2026-8037 – Progress Connection Manager For Objectscale ✓ NVD

CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild
EPSS30% · P98
ActionPatch within 48 hours

Remediation Steps

  1. Apply Progress vendor patch addressing OS command injection flaw
  2. Review access controls to Kemp LoadMaster management interfaces
  3. Monitor system logs for evidence of exploitation attempts
  4. Test patching in a non-production environment first

References:

🛡️CVE-2026-50549 – Anysphere Cursor ✓ NVD

CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild
EPSS1% · P46
ActionPatch within 48 hours

Remediation Steps

  1. Update Cursor to the latest patched version
  2. Disable or restrict execution of untrusted code snippets and prompts
  3. Review Cursor's sandbox configuration and security settings
  4. Educate users on risks of prompt injection attacks

References:

🛡️CVE-2026-45659 – Microsoft SharePoint Server ✓ NVD

CVSS8.8 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild In CISA KEV
EPSS3% · P87
ActionPatch immediately

Remediation Steps

  1. Consult CISA's Known Exploited Vulnerabilities Catalog entry for CVE-2026-45659 to confirm affected versions.
  2. If a patch is not yet available, apply compensating controls such as restricting network access to the affected application.
  3. Monitor logs for unauthorized access attempts targeting this vulnerability.

References:

🛡️CVE-2026-42271 – BerriAI LiteLLM ✓ NVD

CVSS8.8 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild In CISA KEV
EPSS80% · P100
ActionPatch immediately

Remediation Steps

  1. Check CISA's Known Exploited Vulnerabilities catalog for product-specific guidance
  2. Contact vendor for available security patches
  3. Apply patch or implement recommended mitigations from vendor advisory
  4. Verify patch installation and monitor for indicators of active exploitation

References:

🛡️CVE-2026-11645 – Google Chromium V8 ✓ NVD

CVSS8.8 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild In CISA KEV
EPSS2% · P74
ActionPatch immediately

Remediation Steps

  1. Update Google Chrome to version 149.0.7827.103 or later
  2. Enable automatic updates to receive future security patches promptly
  3. Check for and remove any suspicious browser extensions
  4. Clear browser cache and temporary files after patching

References:

🛡️CVE-2026-20230 – Cisco Unified Communications Manager ✓ NVD

CVSS8.6 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild In CISA KEV
EPSS42% · P99
ActionPatch immediately
AffectedTechnology

Remediation Steps

  1. Apply the vendor security update for Cisco Unified Communications Manager Server as a priority.
  2. Restrict network exposure of the affected service to trusted sources until patched.
  3. Review logs and detections for indicators of exploitation.
  4. Confirm fixed versions against the official vendor advisory before deploying.

References:

🛡️CVE-2026-54420 – LiteSpeed CPanel Plugin ✓ NVD

CVSS8.5 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild In CISA KEV
EPSS1% · P66
ActionPatch immediately

Remediation Steps

  1. Apply the patch for the LiteSpeed cPanel user-end plugin to all cPanel servers
  2. Test patched plugin functionality in a staging environment before production deployment
  3. Review server logs for evidence of exploitation attempts
  4. Notify hosting customers of patch deployment timeline

References:

🛡️CVE-2025-48595 – Android Framework ✓ NVD

CVSS8.4 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild In CISA KEV
EPSS2% · P75
ActionPatch immediately
AffectedTechnology Government

Remediation Steps

  1. Apply the vendor security update for Google Android as a priority.
  2. Restrict network exposure of the affected service to trusted sources until patched.
  3. Review logs and detections for indicators of exploitation.
  4. Confirm fixed versions against the official vendor advisory before deploying.

References:

🛡️CVE-2026-20245 – Cisco Catalyst SD-WAN Manager ✓ NVD

CVSS7.8 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild In CISA KEV
EPSS25% · P98
ActionPatch immediately
AffectedGovernment Technology

Remediation Steps

  1. Apply the vendor security update for Cisco Catalyst SD-WAN Manager as a priority.
  2. Restrict network exposure of the affected service to trusted sources until patched.
  3. Review logs and detections for indicators of exploitation.
  4. Confirm fixed versions against the official vendor advisory before deploying.

References:

🛡️CVE-2022-0492 – Linux Kernel ✓ NVD

CVSS7.8 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild In CISA KEV
EPSS6% · P92
ActionPatch immediately
AffectedTechnology Government Energy

Remediation Steps

  1. Identify Linux systems running vulnerable kernel versions
  2. Apply the latest stable kernel update from your distribution's repository
  3. Reboot systems to activate patched kernel
  4. Verify kernel version post-reboot using 'uname -r'
  5. Prioritize kernel patching for systems exposed to untrusted local users or containers

References:

🛡️CVE-2026-28318 – SolarWinds Serv-U ✓ NVD

CVSS7.5 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild In CISA KEV
EPSS11% · P95
ActionPatch immediately

Remediation Steps

  1. Check CISA's Known Exploited Vulnerabilities catalog for product-specific guidance
  2. Contact vendor for available security patches
  3. Apply patch or implement recommended mitigations from vendor advisory
  4. Verify patch installation and monitor for indicators of active exploitation

References:

🛡️CVE-2024-21182 – Oracle WebLogic Server ✓ NVD

CVSS7.5 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild In CISA KEV
EPSS50% · P99
ActionPatch immediately
AffectedTechnology Government

Remediation Steps

  1. Apply the vendor security update for Oracle Weblogic Server as a priority.
  2. Restrict network exposure of the affected service to trusted sources until patched.
  3. Review logs and detections for indicators of exploitation.
  4. Confirm fixed versions against the official vendor advisory before deploying.

References:

🛡️CVE-2026-20262 – Cisco Catalyst SD-WAN Manager ✓ NVD

CVSS6.5 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild In CISA KEV
EPSS8% · P94
ActionPatch immediately
AffectedDefense Technology

Remediation Steps

  1. Apply the vendor security update for Cisco Catalyst SD-WAN Manager as a priority.
  2. Restrict network exposure of the affected service to trusted sources until patched.
  3. Review logs and detections for indicators of exploitation.
  4. Confirm fixed versions against the official vendor advisory before deploying.

References:

🛡️CVE-2026-7473 – Arista Extensible Operating System ✓ NVD

CVSS5.8 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild In CISA KEV
EPSS1% · P53
ActionPatch immediately

Remediation Steps

  1. Apply the vendor security update from Arista
  2. Review network device access logs for unauthorized activity
  3. Restrict management access to network devices from trusted administrative networks

References:

🛡️CVE-2025-5777 – Citrix NetScaler ADC And Gateway ✓ NVD

CVSS7.5 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild In CISA KEV
EPSS100% · P100
ActionPatch immediately
AffectedTechnology

Remediation Steps

  1. Apply the vendor security update for Citrix Bleed 2 (Citrix NetScaler) as a priority.
  2. Restrict network exposure of the affected service to trusted sources until patched.
  3. Review logs and detections for indicators of exploitation.
  4. Confirm fixed versions against the official vendor advisory before deploying.

References:

🛡️CVE-2026-33825 – Microsoft Defender ✓ NVD

CVSS7.8 NVD 3.1
Triage statusActive Exploit
Exploitation In the wild In CISA KEV
EPSS7% · P93
ActionPatch immediately
AffectedTechnology

Remediation Steps

  1. Apply the vendor security update for Microsoft Defender as a priority.
  2. Restrict network exposure of the affected service to trusted sources until patched.
  3. Review logs and detections for indicators of exploitation.
  4. Confirm fixed versions against the official vendor advisory before deploying.

References:

🛡️CVE-2026-8451 – Citrix Netscaler Application Delivery Controller ✓ NVD

CVSS7.5 NVD 3.1
Triage statusNo Known Exploit
ExploitationNo exploitation reported
EPSS1% · P39
ActionPatch this week
AffectedTechnology

Remediation Steps

  1. Apply Citrix security updates to all NetScaler ADC and Gateway instances
  2. Verify the patched version is running on all edge appliances
  3. Restrict network access to NetScaler administrative interfaces
  4. Monitor for unauthorized file access attempts in appliance logs

References:

🛡️CVE-2026-46242 – Linux Kernel ✓ NVD

CVSS7.8 NVD 3.1
Triage statusNo Known Exploit
ExploitationNo exploitation reported
EPSS<1% · P2
ActionPatch this week

Remediation Steps

  1. Identify Linux systems and Android devices affected by the Bad Epoll kernel flaw in your environment.
  2. Check with your Linux distribution vendor and Android device manufacturer for available kernel patches.
  3. Apply the patch to production Linux systems, prioritizing servers and systems with high privilege exposure.
  4. Test patches in a non-production environment before widespread deployment.
  5. Review system logs for suspicious privilege escalation attempts.

References:

🛡️CVE-2026-46331 – Linux Kernel ✓ NVD

CVSS7.8 NVD 3.1
Triage statusNo Known Exploit
ExploitationNo exploitation reported
EPSS<1% · P17
ActionPatch this week
AffectedGovernment Energy

Remediation Steps

  1. Apply the latest Linux kernel security patch addressing the pedit COW out-of-bounds write vulnerability
  2. Verify all systems running affected kernel versions are identified and prioritized
  3. Test patches in staging environment before production deployment
  4. Monitor systems for signs of privilege escalation attempts

References:

🛡️CVE-2026-12957 – Amazon Q Developer ✓ NVD

CVSS7.8 NVD 3.1
Triage statusNo Known Exploit
ExploitationNo exploitation reported
EPSS<1% · P2
ActionPatch this week

Remediation Steps

  1. Update Amazon Q Developer to the patched version
  2. Review workspace trust settings and audit recent repository access
  3. Rotate any cloud credentials that may have been exposed through compromised MCP configurations
  4. Implement code review processes for external and newly-added repositories before workspace activation

References:

🤖 This vulnerability report was compiled by defend.network using AI-powered analysis of vulnerability databases, vendor advisories, and threat intelligence feeds. Always verify remediation steps through official vendor channels before implementing changes in production environments.

Get Vulnerability Priority Updates

Subscribe free and stay on top of critical patches.