Monday, June 15, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Monday's disclosures concentrate on enterprise network, identity, and edge infrastructure from Check Point, Ivanti, Cisco, Oracle, and Arista, alongside a high-severity flaw in Google Chrome. No critical-rated (CVSS 9.0+) CVEs were recorded, down from one the prior day, while high-priority vulnerabilities rose to 56 from 34, a 65% increase. Notable issues include CVE-2026-50751 in Check Point Security Gateway, CVE-2026-10520 in Ivanti Sentry, and CVE-2026-20245 in Cisco Catalyst SD-WAN Manager, each carrying CVSS 9.5 and confirmed exploitation. The activity skews toward perimeter security appliances, SD-WAN management, and identity gateways—systems that, once compromised, expose internal networks and authentication paths. Patches were not yet reflected for the disclosed set (0% availability), so teams should prioritize vendor advisories, compensating controls, and exposure reduction.

  • Enterprise edge and identity infrastructure dominate: Check Point Security Gateway, Ivanti Sentry, Cisco Catalyst SD-WAN Manager, Oracle PeopleSoft, and Arista EOS all affected
  • Critical CVEs fell to 0 from 1 the prior day (-100%)
  • High-priority CVEs climbed to 56 from 34 (+65%)
  • Seven vulnerabilities have confirmed active exploitation, all rated CVSS 9.5, spanning network gateways, SD-WAN management, and a Google Chrome flaw (CVE-2026-11645)
  • Patch availability stands at 0% for the disclosed set; rely on vendor advisories and compensating controls
  • LiteLLM (CVE-2026-42271) exposure highlights growing risk in AI/LLM service components

Immediate action: Prioritize Check Point Security Gateway, Ivanti Sentry, Cisco Catalyst SD-WAN Manager, Oracle PeopleSoft, and Arista EOS for review, and update Google Chrome to the current build. With no patches yet reflected for these disclosures, apply vendor-recommended mitigations, restrict management-plane access, and monitor the seven actively exploited vulnerabilities closely until fixes are confirmed available.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation