Sunday, June 7, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Sunday's disclosures center on high-severity flaws in enterprise infrastructure, with actively exploited weaknesses surfacing in Oracle WebLogic Server, SolarWinds Serv-U, and the Linux kernel. No critical CVEs (CVSS 9.0+) were disclosed, down from 10 the prior day, while high-priority vulnerabilities totaled 23, a 23% decrease from 30. Among the actively exploited issues are CVE-2024-21182 in Oracle WebLogic Server (CVSS 9.5), CVE-2026-28318 in SolarWinds Serv-U (CVSS 9.5), and CVE-2022-0492 in the Linux kernel (CVSS 9.5). The activity spans web application servers, file transfer software, container runtimes, and mobile platforms, with several entries tied to privilege escalation and remote code execution. Patch availability for today's set is limited, so teams should prioritize the exploited items and apply vendor mitigations where fixes are pending.

  • Oracle WebLogic Server, SolarWinds Serv-U, and the Linux kernel headline today's set with confirmed active exploitation
  • No new critical CVEs (CVSS 9.0+), down 100% from 10 the prior day
  • 23 high-priority CVEs disclosed, a 23% decrease from 30
  • Privilege escalation and remote code execution patterns affect web servers, file transfer tools, and container runtimes
  • Patch availability stands at 0% for this set, requiring interim mitigations for unpatched issues
  • 5 actively exploited vulnerabilities span Oracle, SolarWinds, Linux, Android Framework, and a Magento extension

Immediate action: Prioritize Oracle WebLogic Server, SolarWinds Serv-U, Linux kernel, Android Framework, and the Mirasvit Magento cache warmer, as all have confirmed active exploitation. With no patches currently available for today's disclosures, apply vendor-recommended workarounds, restrict exposed services, and monitor affected systems until fixes are released.

How to read this brief

CVSS score (e.g. 9.1) β€” severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability β€” how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical β€” how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges β€” the access they need first. No privileges means no login required.
  • No interaction / User interaction β€” whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale β€” β€œNetwork Β· No privileges Β· No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited β€” confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS Β· Nth percentile β€” FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% β€” a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

πŸ’‘ Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation