Saturday, June 13, 2026

Today's Security Snapshot

Critical vulnerabilities, curated daily for security professionals

🎯 SSCV Profile

See how vulnerabilities affect your specific environment

CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework

Risk scores will be adjusted based on your selected environment

Today's Security Brief

Saturday's disclosures center on three CVSS 10.0 remote code execution flaws affecting SimpleHelp remote support software (CVE-2026-48558), the Aqara IAM/SSO smart-home gateway (CVE-2026-50086), and the vm2 JavaScript sandbox (CVE-2026-47131). Critical-severity vulnerabilities rose 50% to 18, while high-priority issues fell 49% to 31 across 49 total CVEs. Additional critical entries include CVE-2026-54133 (CVSS 9.8) in the jmespath.php library, CVE-2026-50084 (CVSS 9.6) in the Aqara Cloud Production API, and CVE-2026-11849 (CVSS 9.8) in IEI Integration's iRM remote management appliance. The disclosures skew toward sandbox escape, server-side RCE, and IoT/cloud gateway compromise, with several flaws reachable pre-authentication. No fixes were available at disclosure (0% patch availability), and seven CVEs across Ivanti Sentry, Check Point, Oracle PeopleSoft, and Cisco SD-WAN carry confirmed active exploitation.

  • Three CVSS 10.0 RCE flaws disclosed: SimpleHelp (CVE-2026-48558), Aqara IAM/SSO gateway (CVE-2026-50086), and the vm2 sandbox (CVE-2026-47131)
  • Critical CVEs rose 50% to 18, led by widely deployed remote support and smart-home cloud platforms
  • High-priority CVEs fell 49% to 31, with 49 vulnerabilities disclosed in total
  • Attack patterns are dominated by sandbox escape and unauthenticated RCE in jmespath.php (CVE-2026-54133) and IEI iRM remote management (CVE-2026-11849)
  • Patch availability stands at 0% at disclosure, leaving SimpleHelp, Aqara, and vm2 deployments exposed pending vendor fixes
  • Seven CVEs show active exploitation, including Ivanti Sentry (CVE-2026-10520) and Cisco Catalyst SD-WAN Manager (CVE-2026-20245)

Immediate action: Prioritize SimpleHelp remote support servers, Aqara IAM/SSO and cloud API gateways, and any applications bundling the vm2 sandbox or jmespath.php library, as these carry maximum-severity remote code execution risk. With no patches yet available, restrict network exposure of affected services and apply vendor mitigations as released; separately, expedite remediation of the seven actively exploited CVEs affecting Ivanti Sentry, Check Point, Oracle PeopleSoft, and Cisco SD-WAN.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation