Sunday, June 7, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

đŸŽ¯ SSCV Profile

See how vulnerabilities affect your specific environment

CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework

Risk scores will be adjusted based on your selected environment

Archived Security Brief

Sunday's disclosures center on high-severity flaws in enterprise infrastructure, with actively exploited weaknesses surfacing in Oracle WebLogic Server, SolarWinds Serv-U, and the Linux kernel. No critical CVEs (CVSS 9.0+) were disclosed, down from 10 the prior day, while high-priority vulnerabilities totaled 23, a 23% decrease from 30. Among the actively exploited issues are CVE-2024-21182 in Oracle WebLogic Server (CVSS 9.5), CVE-2026-28318 in SolarWinds Serv-U (CVSS 9.5), and CVE-2022-0492 in the Linux kernel (CVSS 9.5). The activity spans web application servers, file transfer software, container runtimes, and mobile platforms, with several entries tied to privilege escalation and remote code execution. Patch availability for today's set is limited, so teams should prioritize the exploited items and apply vendor mitigations where fixes are pending.

  • Oracle WebLogic Server, SolarWinds Serv-U, and the Linux kernel headline today's set with confirmed active exploitation
  • No new critical CVEs (CVSS 9.0+), down 100% from 10 the prior day
  • 23 high-priority CVEs disclosed, a 23% decrease from 30
  • Privilege escalation and remote code execution patterns affect web servers, file transfer tools, and container runtimes
  • Patch availability stands at 0% for this set, requiring interim mitigations for unpatched issues
  • 5 actively exploited vulnerabilities span Oracle, SolarWinds, Linux, Android Framework, and a Magento extension

Immediate action: Prioritize Oracle WebLogic Server, SolarWinds Serv-U, Linux kernel, Android Framework, and the Mirasvit Magento cache warmer, as all have confirmed active exploitation. With no patches currently available for today's disclosures, apply vendor-recommended workarounds, restrict exposed services, and monitor affected systems until fixes are released.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation