Tuesday, June 2, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Tuesday's brief is led by CVSS 10.0 vulnerabilities in CloudPirates Open Source Helm Charts (CVE-2026-45131, CVE-2026-45132) and Cloud Foundry UAA (CVE-2026-40965), exposing container deployment pipelines and identity services to compromise. Critical CVEs rose sharply to 9 from 2 the prior day (+350%), while high-priority disclosures fell to 46 from 70 (-34%). Additional critical entries include CVE-2026-25879 (CVSS 9.8) in the Langroid framework and CVE-2026-8206 (CVSS 9.8) in the WordPress Kirki plugin, both enabling remote attack paths against widely deployed software. Web application plugins, AI/ML frameworks, and CI/CD identity components dominate the day's disclosures, with remote code execution and authentication weaknesses as the recurring patterns. No patches are currently flagged as available across this set, so affected operators should prioritize compensating controls and monitor vendor advisories; six CVEs are listed in CISA KEV as actively exploited, spanning PAN-OS, Oracle WebLogic, and the LiteSpeed cPanel plugin.

  • Three CVSS 10.0 flaws affect CloudPirates Open Source Helm Charts (CVE-2026-45131, CVE-2026-45132) and Cloud Foundry UAA (CVE-2026-40965), impacting container deployment and identity infrastructure
  • Critical CVEs increased to 9 from 2 the prior day (+350%)
  • High-priority CVEs decreased to 46 from 70 the prior day (-34%)
  • Remote code execution and authentication bypass dominate, hitting the Langroid framework (CVE-2026-25879), WordPress Kirki plugin (CVE-2026-8206), and Dassault Systèmes Teamwork Cloud (CVE-2026-7858)
  • Patch availability stands at 0% across the disclosed set, requiring interim mitigations and advisory monitoring
  • Six CVEs appear in CISA KEV as actively exploited, including Palo Alto Networks PAN-OS (CVE-2026-0257) and Oracle WebLogic Server (CVE-2024-21182)

Immediate action: Prioritize CloudPirates Helm Charts, Cloud Foundry UAA, and the actively exploited PAN-OS, Oracle WebLogic, and LiteSpeed cPanel deployments for immediate review and isolation. With no patches currently available for the critical set, apply vendor-recommended workarounds, restrict network exposure of affected services, and increase monitoring on identity and CI/CD systems until fixes ship.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation