Tuesday, June 16, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

A large set of CRM Perks WordPress integration plugins—covering Salesforce, Zendesk, HubSpot, Keap/Infusionsoft, Mailchimp, and Constant Contact connectors—account for most of the day's critical disclosures, each rated CVSS 9.8. The brief includes 30 critical CVEs, up from none the prior day, and 62 high-priority CVEs, an 11% increase over the previous 56. Notable critical entries include CVE-2026-48114 in DataONE Metacat (CVSS 9.8), CVE-2026-49109 in CRM Perks Integration for Salesforce (CVSS 9.8), and CVE-2018-25436 in the Baggage Freight Shipping Australia WordPress plugin (CVSS 9.8). Active exploitation spans enterprise infrastructure, with KEV-listed flaws in Cisco Catalyst SD-WAN Manager, Ivanti Sentry, Oracle PeopleSoft PeopleTools, Arista EOS, and Microsoft Exchange Server. No patches are currently flagged as available across these disclosures, so teams should prioritize mitigations and exposure reduction while monitoring vendors for fixes.

  • Nine CRM Perks WordPress integration plugins (Salesforce, Zendesk, HubSpot, Keap, Mailchimp, Constant Contact, and others) disclosed at CVSS 9.8
  • 30 critical CVEs disclosed, up from 0 the prior day
  • 62 high-priority CVEs, an 11% increase from 56
  • Remote, unauthenticated attack patterns dominate, including CVE-2026-48114 in DataONE Metacat and CVE-2026-27053 in WordPress Broadcast Live Video
  • Patch availability stands at 0% across today's disclosures, requiring interim mitigations
  • Nine actively exploited CVEs affect Cisco Catalyst SD-WAN Manager, Ivanti Sentry, Oracle PeopleSoft, Arista EOS, and Microsoft Exchange Server

Immediate action: Prioritize the actively exploited enterprise systems—Cisco Catalyst SD-WAN Manager, Ivanti Sentry, Oracle PeopleSoft PeopleTools, Arista EOS, and Microsoft Exchange Server—for immediate review and mitigation, and audit WordPress sites running CRM Perks integration plugins or the affected DataONE Metacat and Broadcast Live Video components. With no patches currently available across these disclosures, apply vendor mitigations, restrict exposure of affected services, and monitor advisories for forthcoming fixes.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation