Monday, June 15, 2026

Today's Security Snapshot

Critical vulnerabilities, curated daily for security professionals

🎯 SSCV Profile

See how vulnerabilities affect your specific environment

CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework

Risk scores will be adjusted based on your selected environment

Today's Security Brief

Monday's disclosures concentrate on enterprise network, identity, and edge infrastructure from Check Point, Ivanti, Cisco, Oracle, and Arista, alongside a high-severity flaw in Google Chrome. No critical-rated (CVSS 9.0+) CVEs were recorded, down from one the prior day, while high-priority vulnerabilities rose to 56 from 34, a 65% increase. Notable issues include CVE-2026-50751 in Check Point Security Gateway, CVE-2026-10520 in Ivanti Sentry, and CVE-2026-20245 in Cisco Catalyst SD-WAN Manager, each carrying CVSS 9.5 and confirmed exploitation. The activity skews toward perimeter security appliances, SD-WAN management, and identity gateways—systems that, once compromised, expose internal networks and authentication paths. Patches were not yet reflected for the disclosed set (0% availability), so teams should prioritize vendor advisories, compensating controls, and exposure reduction.

  • Enterprise edge and identity infrastructure dominate: Check Point Security Gateway, Ivanti Sentry, Cisco Catalyst SD-WAN Manager, Oracle PeopleSoft, and Arista EOS all affected
  • Critical CVEs fell to 0 from 1 the prior day (-100%)
  • High-priority CVEs climbed to 56 from 34 (+65%)
  • Seven vulnerabilities have confirmed active exploitation, all rated CVSS 9.5, spanning network gateways, SD-WAN management, and a Google Chrome flaw (CVE-2026-11645)
  • Patch availability stands at 0% for the disclosed set; rely on vendor advisories and compensating controls
  • LiteLLM (CVE-2026-42271) exposure highlights growing risk in AI/LLM service components

Immediate action: Prioritize Check Point Security Gateway, Ivanti Sentry, Cisco Catalyst SD-WAN Manager, Oracle PeopleSoft, and Arista EOS for review, and update Google Chrome to the current build. With no patches yet reflected for these disclosures, apply vendor-recommended mitigations, restrict management-plane access, and monitor the seven actively exploited vulnerabilities closely until fixes are confirmed available.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation