Thursday, June 18, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Oracle products account for the bulk of Thursday's critical disclosures, spanning WebLogic Server, Coherence, Solaris, WebCenter Enterprise Capture, and the Fusion Middleware Identity Manager Connector. The day brought 48 critical CVEs (up from 2 the prior day) and 90 high-priority CVEs (up from 26), reflecting a large batch of enterprise platform disclosures. Notable entries include CVE-2026-35292 (CVSS 10) and CVE-2026-35301 (CVSS 10) in Oracle WebLogic Server, CVE-2026-46978 (CVSS 10) in Oracle Solaris, and CVE-2026-46794 (CVSS 9.9) in the Oracle Fusion Middleware Identity Manager Connector. WordPress ecosystem plugins also feature prominently, with CVE-2025-69129 (CVSS 10) in the WooCommerce Scraper plugin and CVE-2026-25470 (CVSS 10) in the ACPT Custom Post Types plugin, alongside five vulnerabilities under active exploitation across Ivanti Sentry, Oracle PeopleSoft, Cisco Catalyst SD-WAN Manager, and others. No patches were recorded as available at disclosure time, so affected organizations should prioritize inventory and compensating controls while monitoring vendor advisories.

  • Oracle enterprise platforms (WebLogic Server, Coherence, Solaris, WebCenter Enterprise Capture) drive the day's critical disclosures, several rated CVSS 10
  • Critical CVEs rose to 48 from 2 the prior day (2300% increase)
  • High-priority CVEs rose to 90 from 26 the prior day (246% increase)
  • Remote code execution and authentication bypass patterns affect Oracle middleware and multiple WordPress plugins (WooCommerce Scraper, ACPT Custom Post Types)
  • Patches available for 0% of disclosed CVEs; affected systems include Oracle Fusion Middleware, Solaris, and Coherence
  • Five vulnerabilities are under active exploitation, including Ivanti Sentry, Cisco Catalyst SD-WAN Manager, and Oracle PeopleSoft

Immediate action: Prioritize Oracle WebLogic Server, Coherence, Solaris, and WebCenter Enterprise Capture deployments along with the affected WordPress plugins for review and isolation. With no patches yet available for these disclosures, apply network restrictions and access controls to exposed instances and patch the actively exploited Ivanti Sentry, Cisco Catalyst SD-WAN Manager, and Oracle PeopleSoft systems as vendor fixes are released.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation