Tuesday, June 9, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

SAP NetWeaver Application Server ABAP and Apache HTTP Server anchor Tuesday's disclosures, with SAP CVE-2026-44748 (CVSS 9.9) and Apache CVE-2026-44631 (CVSS 9.8) exposing widely deployed enterprise and web-facing systems to remote compromise. The day brought 12 critical CVEs, up from 3 the prior day (+300%), alongside 62 high-priority CVEs, up from 33 (+88%). Google Chrome accounted for a cluster of critical browser flaws including CVE-2026-11634 and CVE-2026-11638 (both CVSS 9.6), while CVE-2026-27671 (CVSS 9.8) marks a second critical SAP NetWeaver ABAP issue and CVE-2026-11499 (CVSS 9.8) affects Tenda HG-series routers. Remote code execution and unauthenticated access dominate the high-impact set, spanning enterprise application servers, web servers, browsers, and edge networking hardware. No patches were recorded as available at disclosure across this set, and six CVEsβ€”including issues in the Linux Kernel, Android Framework, Check Point Security Gateway, and SolarWinds Serv-Uβ€”are under active exploitation, warranting a treat-as-unpatched, mitigation-first posture.

  • SAP NetWeaver Application Server ABAP carries two critical flaws (CVE-2026-44748 at CVSS 9.9 and CVE-2026-27671 at CVSS 9.8), placing core ERP infrastructure at highest exposure
  • Critical CVEs rose to 12 from 3 the prior day, a 300% increase
  • High-priority CVEs climbed to 62 from 33, an 88% increase
  • Remote code execution and unauthenticated access patterns dominate, affecting Apache HTTP Server (CVE-2026-44631), Google Chrome (CVE-2026-11634, CVE-2026-11638), and Tenda HG-series routers (CVE-2026-11499)
  • Patch availability stands at 0% across this disclosure set, requiring compensating controls and exposure reduction in the interim
  • Six CVEs show active exploitation, including the Linux Kernel, Android Framework, Check Point Security Gateway, and SolarWinds Serv-U

Immediate action: Prioritize SAP NetWeaver ABAP, Apache HTTP Server, and internet-facing Tenda routers for immediate review, and update Chrome through managed channels as fixes ship. With no patches available at disclosure, apply vendor mitigations, restrict network exposure of affected services, and monitor the actively exploited Linux Kernel, Android, Check Point, and SolarWinds Serv-U issues closely.

How to read this brief

CVSS score (e.g. 9.1) β€” severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability β€” how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical β€” how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges β€” the access they need first. No privileges means no login required.
  • No interaction / User interaction β€” whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale β€” β€œNetwork Β· No privileges Β· No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited β€” confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS Β· Nth percentile β€” FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% β€” a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

πŸ’‘ Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation