Monday, June 1, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

OTRS Community Edition and Totolink networking hardware anchor today's disclosures, with high-severity flaws spanning web management consoles, edge routers, and developer tooling. Disclosures included 2 critical CVEs (up from 1, a 100% increase) and 70 high-priority CVEs (up from 30, a 133% increase). CVE-2026-10187 (CVSS 9.8) affects the Totolink N300RH router and CVE-2026-48188 (CVSS 9.1) impacts OTRS and OTRS Community Edition, both carrying remote attack potential. Several actively exploited issues touch widely deployed infrastructure, including Palo Alto Networks PAN-OS (CVE-2026-0257) and the LiteSpeed cPanel plugin (CVE-2026-48172). No patches were available at disclosure for the cataloged items, so teams should prioritize compensating controls and exposure reduction while vendor fixes are pending.

  • Totolink N300RH router carries the day's highest-rated flaw, CVE-2026-10187 (CVSS 9.8), with OTRS Community Edition close behind at CVSS 9.1
  • Critical CVEs rose to 2, a 100% increase over the prior day's single critical disclosure
  • High-priority CVEs climbed to 70, a 133% increase from 30 the previous day
  • Affected products span web/server management (OTRS, LiteSpeed cPanel plugin), edge networking (Totolink, PAN-OS), and developer tooling (Nx Console, GitHub Actions OIDC)
  • Patch availability stands at 0% across cataloged items, leaving mitigation and access restriction as the primary near-term defenses
  • Five vulnerabilities show confirmed active exploitation, including PAN-OS (CVE-2026-0257) and the LiteSpeed cPanel plugin (CVE-2026-48172)

Immediate action: Prioritize exposure review for Totolink edge routers, OTRS/OTRS Community Edition consoles, and Palo Alto Networks PAN-OS, restricting management interfaces to trusted networks. With no patches available at disclosure, apply vendor workarounds, tighten access controls, and monitor the actively exploited PAN-OS and LiteSpeed cPanel plugin issues closely until fixes ship.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation