Thursday, June 4, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

OpenStack Mistral (CVE-2026-41283, CVSS 9.9) and ABB T-MAC Plus (CVE-2025-14771, CVSS 9.9) lead the day's disclosures, exposing cloud orchestration and industrial monitoring systems to severe compromise. Five critical CVEs were disclosed, down 29% from the prior day's seven, while high-priority vulnerabilities rose 218% to 54 from 17. Additional critical flaws include CVE-2026-47065 (CVSS 9.8) and CVE-2026-36576 (CVSS 9.8) in Openlabs docker-wkhtmltopdf-aas, broadening exposure across containerized and multi-product deployments. The disclosures span cloud platforms, industrial control software, and web infrastructure, with several actively exploited issues affecting Palo Alto Networks PAN-OS and Oracle WebLogic Server. Patches are not yet reflected as available across this set, so organizations should prioritize compensating controls and monitoring while vendor fixes are confirmed.

  • OpenStack Mistral (CVE-2026-41283, CVSS 9.9) and ABB T-MAC Plus (CVE-2025-14771, CVSS 9.9) headline the day, impacting cloud orchestration and industrial monitoring
  • 5 critical CVEs disclosed, down 29% from the prior day's 7
  • 54 high-priority CVEs disclosed, up 218% from 17 the prior day
  • Critical flaws in Openlabs docker-wkhtmltopdf-aas (CVE-2026-36576) and multiple products (CVE-2026-47065, CVE-2026-35075) raise risk for containerized and web-facing systems
  • Patch availability stands at 0% across this set, requiring interim mitigations and close monitoring
  • 5 vulnerabilities show active exploitation, including Palo Alto Networks PAN-OS, Oracle WebLogic Server, and Linux Kernel

Immediate action: Prioritize OpenStack Mistral, ABB T-MAC Plus, and Openlabs docker-wkhtmltopdf-aas deployments for immediate review, alongside actively exploited Palo Alto Networks PAN-OS and Oracle WebLogic Server systems. With patches not yet available for this set, apply vendor-recommended mitigations, restrict network exposure, and increase monitoring on affected services until fixes are confirmed.

How to read this brief

CVSS score (e.g. 9.1) β€” severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability β€” how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical β€” how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges β€” the access they need first. No privileges means no login required.
  • No interaction / User interaction β€” whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale β€” β€œNetwork Β· No privileges Β· No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited β€” confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS Β· Nth percentile β€” FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% β€” a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

πŸ’‘ Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation