Tuesday, June 16, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

🎯 SSCV Profile

See how vulnerabilities affect your specific environment

CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework

Risk scores will be adjusted based on your selected environment

Archived Security Brief

A large set of CRM Perks WordPress integration plugins—covering Salesforce, Zendesk, HubSpot, Keap/Infusionsoft, Mailchimp, and Constant Contact connectors—account for most of the day's critical disclosures, each rated CVSS 9.8. The brief includes 30 critical CVEs, up from none the prior day, and 62 high-priority CVEs, an 11% increase over the previous 56. Notable critical entries include CVE-2026-48114 in DataONE Metacat (CVSS 9.8), CVE-2026-49109 in CRM Perks Integration for Salesforce (CVSS 9.8), and CVE-2018-25436 in the Baggage Freight Shipping Australia WordPress plugin (CVSS 9.8). Active exploitation spans enterprise infrastructure, with KEV-listed flaws in Cisco Catalyst SD-WAN Manager, Ivanti Sentry, Oracle PeopleSoft PeopleTools, Arista EOS, and Microsoft Exchange Server. No patches are currently flagged as available across these disclosures, so teams should prioritize mitigations and exposure reduction while monitoring vendors for fixes.

  • Nine CRM Perks WordPress integration plugins (Salesforce, Zendesk, HubSpot, Keap, Mailchimp, Constant Contact, and others) disclosed at CVSS 9.8
  • 30 critical CVEs disclosed, up from 0 the prior day
  • 62 high-priority CVEs, an 11% increase from 56
  • Remote, unauthenticated attack patterns dominate, including CVE-2026-48114 in DataONE Metacat and CVE-2026-27053 in WordPress Broadcast Live Video
  • Patch availability stands at 0% across today's disclosures, requiring interim mitigations
  • Nine actively exploited CVEs affect Cisco Catalyst SD-WAN Manager, Ivanti Sentry, Oracle PeopleSoft, Arista EOS, and Microsoft Exchange Server

Immediate action: Prioritize the actively exploited enterprise systems—Cisco Catalyst SD-WAN Manager, Ivanti Sentry, Oracle PeopleSoft PeopleTools, Arista EOS, and Microsoft Exchange Server—for immediate review and mitigation, and audit WordPress sites running CRM Perks integration plugins or the affected DataONE Metacat and Broadcast Live Video components. With no patches currently available across these disclosures, apply vendor mitigations, restrict exposure of affected services, and monitor advisories for forthcoming fixes.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation