Sunday, June 14, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

🎯 SSCV Profile

See how vulnerabilities affect your specific environment

CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework

Risk scores will be adjusted based on your selected environment

Archived Security Brief

Sunday's disclosures center on industrial control systems and enterprise network infrastructure, headlined by a critical flaw in Nefteprodukttekhnika's BUK TS-G gas station automation system alongside actively exploited weaknesses in Ivanti, Check Point, and Cisco edge devices. The day brought 1 critical vulnerability, down 94% from the prior day's 18, and 34 high-priority CVEs, up 10% from 31. Notable named issues include CVE-2026-12183 (CVSS 9.8) in the BUK TS-G automation platform, CVE-2026-10520 (CVSS 10) in Ivanti Sentry, and CVE-2026-35273 (CVSS 9.8) in Oracle PeopleSoft Enterprise PeopleTools. Attack patterns skew toward remote code execution and authentication bypass against perimeter security appliances and management consoles. No patches were available at disclosure for the day's CVEs, warranting prioritized monitoring and compensating controls for exposed systems.

  • Critical flaw CVE-2026-12183 (CVSS 9.8) affects Nefteprodukttekhnika BUK TS-G gas station automation, exposing industrial control infrastructure
  • Critical CVE count fell to 1, a 94% decrease from the prior day's 18
  • High-priority CVEs rose to 34, a 10% increase from 31 the prior day
  • Remote code execution and authentication bypass dominate, targeting Ivanti Sentry (CVE-2026-10520, CVSS 10), Check Point Security Gateway, and Cisco Catalyst SD-WAN Manager
  • Patch availability stands at 0% across the day's disclosures, requiring interim mitigations for affected systems
  • 7 vulnerabilities are confirmed under active exploitation, spanning Ivanti, Check Point, Oracle, Cisco, Arista, Google Chrome, and LiteLLM

Immediate action: Prioritize exposed Ivanti Sentry, Check Point Security Gateway, Oracle PeopleSoft, and Cisco Catalyst SD-WAN Manager instances, all under active exploitation, and isolate the BUK TS-G industrial automation system from untrusted networks. With no patches currently available, apply vendor workarounds, restrict management interface access, and increase monitoring on perimeter and ICS assets until fixes ship.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation