Thursday, June 4, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

🎯 SSCV Profile

See how vulnerabilities affect your specific environment

CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework

Risk scores will be adjusted based on your selected environment

Archived Security Brief

OpenStack Mistral (CVE-2026-41283, CVSS 9.9) and ABB T-MAC Plus (CVE-2025-14771, CVSS 9.9) lead the day's disclosures, exposing cloud orchestration and industrial monitoring systems to severe compromise. Five critical CVEs were disclosed, down 29% from the prior day's seven, while high-priority vulnerabilities rose 218% to 54 from 17. Additional critical flaws include CVE-2026-47065 (CVSS 9.8) and CVE-2026-36576 (CVSS 9.8) in Openlabs docker-wkhtmltopdf-aas, broadening exposure across containerized and multi-product deployments. The disclosures span cloud platforms, industrial control software, and web infrastructure, with several actively exploited issues affecting Palo Alto Networks PAN-OS and Oracle WebLogic Server. Patches are not yet reflected as available across this set, so organizations should prioritize compensating controls and monitoring while vendor fixes are confirmed.

  • OpenStack Mistral (CVE-2026-41283, CVSS 9.9) and ABB T-MAC Plus (CVE-2025-14771, CVSS 9.9) headline the day, impacting cloud orchestration and industrial monitoring
  • 5 critical CVEs disclosed, down 29% from the prior day's 7
  • 54 high-priority CVEs disclosed, up 218% from 17 the prior day
  • Critical flaws in Openlabs docker-wkhtmltopdf-aas (CVE-2026-36576) and multiple products (CVE-2026-47065, CVE-2026-35075) raise risk for containerized and web-facing systems
  • Patch availability stands at 0% across this set, requiring interim mitigations and close monitoring
  • 5 vulnerabilities show active exploitation, including Palo Alto Networks PAN-OS, Oracle WebLogic Server, and Linux Kernel

Immediate action: Prioritize OpenStack Mistral, ABB T-MAC Plus, and Openlabs docker-wkhtmltopdf-aas deployments for immediate review, alongside actively exploited Palo Alto Networks PAN-OS and Oracle WebLogic Server systems. With patches not yet available for this set, apply vendor-recommended mitigations, restrict network exposure, and increase monitoring on affected services until fixes are confirmed.

πŸ’‘ Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation