Wednesday, June 17, 2026

Today's Security Snapshot

Critical vulnerabilities, curated daily for security professionals

🎯 SSCV Profile

See how vulnerabilities affect your specific environment

CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework

Risk scores will be adjusted based on your selected environment

Today's Security Brief

Networking infrastructure leads Wednesday's disclosures, with two CVSS 10 flaws in Cisco Catalyst SD-WAN (CVE-2026-20127 and CVE-2026-20182) confirmed under active exploitation alongside the related SD-WAN Manager issue CVE-2026-20262. The set totals 28 vulnerabilities, including 2 rated critical (down 93% from 30) and 26 high-priority (down 58% from 62). The remaining critical entries affect web applications, namely CVE-2026-49774 (CVSS 9.9) in Filipe Nasc RD Station and CVE-2026-40750 (CVSS 9.9) in the themagnifico52 Kids Online Store. Active exploitation extends beyond Cisco to Ivanti Sentry (CVE-2026-10520), Oracle PeopleSoft PeopleTools (CVE-2026-35273), and the Joomla Content Editor (CVE-2026-48907), indicating attacker interest in both edge gateways and content-management plugins. No patches were available across the disclosed set at publication, so organizations should prioritize mitigation, access restriction, and monitoring while fixes are pending.

  • Cisco Catalyst SD-WAN carries two CVSS 10 flaws, CVE-2026-20127 and CVE-2026-20182, both under active exploitation
  • 2 critical CVEs disclosed, down 93% from 30 the prior day
  • 26 high-priority CVEs disclosed, down 58% from 62 the prior day
  • Web application flaws CVE-2026-49774 (RD Station) and CVE-2026-40750 (Kids Online Store) both reach CVSS 9.9
  • Patch availability stands at 0%, requiring mitigation and access controls for Cisco, Ivanti Sentry, and Oracle PeopleSoft
  • 7 vulnerabilities show confirmed active exploitation, spanning network gateways and CMS plugins

Immediate action: Prioritize Cisco Catalyst SD-WAN and SD-WAN Manager, Ivanti Sentry, and Oracle PeopleSoft PeopleTools, which face active exploitation at CVSS 9.5 and above. With no patches currently available, restrict management-interface access, apply vendor workarounds, and increase monitoring on affected systems until fixes ship.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation