Sunday, June 21, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

🎯 SSCV Profile

See how vulnerabilities affect your specific environment

CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework

Risk scores will be adjusted based on your selected environment

Archived Security Brief

Sunday's disclosures center on web-facing applications and developer infrastructure, with critical remote-code-execution and access-control flaws affecting WooCommerce, Prefect, and Flowise alongside several widely deployed WordPress plugins. The day brought 5 critical CVEs, down 37% from the prior day's 8, while high-priority volume rose 43% to 67. Notable entries include CVE-2026-5366 (CVSS 9.9) in Prefect, CVE-2022-50972 (CVSS 9.8) in WooCommerce, and CVE-2024-58351 (CVSS 9.8) in Flowise. Plugin- and platform-level weaknesses dominate the set, exposing content-management and workflow-orchestration systems to unauthenticated compromise, and four CVEs carry confirmed active exploitation across LiteSpeed, Joomla, Splunk, and Cisco SD-WAN Manager. No patches were referenced at disclosure for the scored set, so teams should prioritize compensating controls and vendor monitoring while fixes are validated.

  • Developer and orchestration infrastructure leads the day, with CVE-2026-5366 (CVSS 9.9) in Prefect and CVE-2024-58351 (CVSS 9.8) in Flowise exposing automation platforms to remote compromise
  • 5 critical CVEs disclosed, a 37% decrease from the prior day's 8
  • 67 high-priority CVEs disclosed, a 43% increase from the prior day's 47
  • Remote code execution and access-control bypass dominate, affecting WooCommerce, Branda, and multiple WordPress plugins
  • Patch availability stands at 0% across the scored set, leaving web-application and orchestration systems reliant on mitigations
  • Four CVEs show active exploitation, spanning LiteSpeed cPanel plugin, Joomla Content Editor, Splunk Enterprise/Cloud, and Cisco Catalyst SD-WAN Manager

Immediate action: Prioritize WordPress/WooCommerce environments, Prefect and Flowise deployments, and the actively exploited Splunk, Cisco SD-WAN Manager, LiteSpeed, and Joomla systems for immediate review and isolation where exposed. With no patches referenced at disclosure, apply WAF rules, restrict administrative and internet-facing access, and monitor vendor advisories closely for forthcoming fixes.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation