Wednesday, June 17, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Networking infrastructure leads Wednesday's disclosures, with two CVSS 10 flaws in Cisco Catalyst SD-WAN (CVE-2026-20127 and CVE-2026-20182) confirmed under active exploitation alongside the related SD-WAN Manager issue CVE-2026-20262. The set totals 28 vulnerabilities, including 2 rated critical (down 93% from 30) and 26 high-priority (down 58% from 62). The remaining critical entries affect web applications, namely CVE-2026-49774 (CVSS 9.9) in Filipe Nasc RD Station and CVE-2026-40750 (CVSS 9.9) in the themagnifico52 Kids Online Store. Active exploitation extends beyond Cisco to Ivanti Sentry (CVE-2026-10520), Oracle PeopleSoft PeopleTools (CVE-2026-35273), and the Joomla Content Editor (CVE-2026-48907), indicating attacker interest in both edge gateways and content-management plugins. No patches were available across the disclosed set at publication, so organizations should prioritize mitigation, access restriction, and monitoring while fixes are pending.

  • Cisco Catalyst SD-WAN carries two CVSS 10 flaws, CVE-2026-20127 and CVE-2026-20182, both under active exploitation
  • 2 critical CVEs disclosed, down 93% from 30 the prior day
  • 26 high-priority CVEs disclosed, down 58% from 62 the prior day
  • Web application flaws CVE-2026-49774 (RD Station) and CVE-2026-40750 (Kids Online Store) both reach CVSS 9.9
  • Patch availability stands at 0%, requiring mitigation and access controls for Cisco, Ivanti Sentry, and Oracle PeopleSoft
  • 7 vulnerabilities show confirmed active exploitation, spanning network gateways and CMS plugins

Immediate action: Prioritize Cisco Catalyst SD-WAN and SD-WAN Manager, Ivanti Sentry, and Oracle PeopleSoft PeopleTools, which face active exploitation at CVSS 9.5 and above. With no patches currently available, restrict management-interface access, apply vendor workarounds, and increase monitoring on affected systems until fixes ship.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation