Saturday, June 13, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Saturday's disclosures center on three CVSS 10.0 remote code execution flaws affecting SimpleHelp remote support software (CVE-2026-48558), the Aqara IAM/SSO smart-home gateway (CVE-2026-50086), and the vm2 JavaScript sandbox (CVE-2026-47131). Critical-severity vulnerabilities rose 50% to 18, while high-priority issues fell 49% to 31 across 49 total CVEs. Additional critical entries include CVE-2026-54133 (CVSS 9.8) in the jmespath.php library, CVE-2026-50084 (CVSS 9.6) in the Aqara Cloud Production API, and CVE-2026-11849 (CVSS 9.8) in IEI Integration's iRM remote management appliance. The disclosures skew toward sandbox escape, server-side RCE, and IoT/cloud gateway compromise, with several flaws reachable pre-authentication. No fixes were available at disclosure (0% patch availability), and seven CVEs across Ivanti Sentry, Check Point, Oracle PeopleSoft, and Cisco SD-WAN carry confirmed active exploitation.

  • Three CVSS 10.0 RCE flaws disclosed: SimpleHelp (CVE-2026-48558), Aqara IAM/SSO gateway (CVE-2026-50086), and the vm2 sandbox (CVE-2026-47131)
  • Critical CVEs rose 50% to 18, led by widely deployed remote support and smart-home cloud platforms
  • High-priority CVEs fell 49% to 31, with 49 vulnerabilities disclosed in total
  • Attack patterns are dominated by sandbox escape and unauthenticated RCE in jmespath.php (CVE-2026-54133) and IEI iRM remote management (CVE-2026-11849)
  • Patch availability stands at 0% at disclosure, leaving SimpleHelp, Aqara, and vm2 deployments exposed pending vendor fixes
  • Seven CVEs show active exploitation, including Ivanti Sentry (CVE-2026-10520) and Cisco Catalyst SD-WAN Manager (CVE-2026-20245)

Immediate action: Prioritize SimpleHelp remote support servers, Aqara IAM/SSO and cloud API gateways, and any applications bundling the vm2 sandbox or jmespath.php library, as these carry maximum-severity remote code execution risk. With no patches yet available, restrict network exposure of affected services and apply vendor mitigations as released; separately, expedite remediation of the seven actively exploited CVEs affecting Ivanti Sentry, Check Point, Oracle PeopleSoft, and Cisco SD-WAN.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation