Wednesday, June 3, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Progress Sitefinity led Wednesday's disclosures with two critical vulnerabilities, including CVE-2026-7312 at the maximum CVSS 10 and CVE-2026-7198 at 9.8, placing content-management deployments at the front of remediation queues. The day brought 7 critical CVEs, down 22% from the prior day's 9, and 17 high-priority CVEs, down 63% from 46. Beyond Sitefinity, critical issues affected identity and healthcare systems, including CVE-2026-49448 (9.8) in authentik, CVE-2026-0611 (9.8) in Spacelabs Healthcare Sentinel, and CVE-2026-47117 (9.8) in OpenMed. Remote code execution and authentication bypass dominated the critical set, spanning web platforms, WordPress/LMS plugins, and medical devices. No patches were available at disclosure for the reported critical issues, so teams should prioritize compensating controls and monitor vendor advisories closely; 7 CVEs carry confirmed active exploitation, including Palo Alto Networks PAN-OS and Oracle WebLogic Server.

  • Progress Sitefinity carried two critical flaws, CVE-2026-7312 (CVSS 10) and CVE-2026-7198 (CVSS 9.8), making it the most exposed platform of the day
  • Critical CVEs totaled 7, a 22% decrease from the prior day's 9
  • High-priority CVEs totaled 17, a 63% decrease from the prior day's 46
  • Remote code execution and authentication bypass were the dominant attack patterns, affecting web CMS, identity (authentik), and LMS/WordPress plugins
  • Patch availability stood at 0% for the disclosed critical issues, leaving compensating controls and monitoring as the primary near-term defense
  • 7 CVEs have confirmed active exploitation, including Palo Alto Networks PAN-OS (CVE-2026-0257) and Oracle WebLogic Server (CVE-2024-21182)

Immediate action: Prioritize Progress Sitefinity, authentik, and internet-facing healthcare systems (Spacelabs Sentinel, OpenMed) for immediate review, and apply restrictions or isolation where fixes are not yet published. With patch availability at 0% for the disclosed critical issues, track vendor advisories continuously and apply mitigations as soon as they are released; separately, ensure actively exploited products such as Palo Alto Networks PAN-OS and Oracle WebLogic Server are remediated on an accelerated timeline.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation