Sunday, June 21, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Sunday's disclosures center on web-facing applications and developer infrastructure, with critical remote-code-execution and access-control flaws affecting WooCommerce, Prefect, and Flowise alongside several widely deployed WordPress plugins. The day brought 5 critical CVEs, down 37% from the prior day's 8, while high-priority volume rose 43% to 67. Notable entries include CVE-2026-5366 (CVSS 9.9) in Prefect, CVE-2022-50972 (CVSS 9.8) in WooCommerce, and CVE-2024-58351 (CVSS 9.8) in Flowise. Plugin- and platform-level weaknesses dominate the set, exposing content-management and workflow-orchestration systems to unauthenticated compromise, and four CVEs carry confirmed active exploitation across LiteSpeed, Joomla, Splunk, and Cisco SD-WAN Manager. No patches were referenced at disclosure for the scored set, so teams should prioritize compensating controls and vendor monitoring while fixes are validated.

  • Developer and orchestration infrastructure leads the day, with CVE-2026-5366 (CVSS 9.9) in Prefect and CVE-2024-58351 (CVSS 9.8) in Flowise exposing automation platforms to remote compromise
  • 5 critical CVEs disclosed, a 37% decrease from the prior day's 8
  • 67 high-priority CVEs disclosed, a 43% increase from the prior day's 47
  • Remote code execution and access-control bypass dominate, affecting WooCommerce, Branda, and multiple WordPress plugins
  • Patch availability stands at 0% across the scored set, leaving web-application and orchestration systems reliant on mitigations
  • Four CVEs show active exploitation, spanning LiteSpeed cPanel plugin, Joomla Content Editor, Splunk Enterprise/Cloud, and Cisco Catalyst SD-WAN Manager

Immediate action: Prioritize WordPress/WooCommerce environments, Prefect and Flowise deployments, and the actively exploited Splunk, Cisco SD-WAN Manager, LiteSpeed, and Joomla systems for immediate review and isolation where exposed. With no patches referenced at disclosure, apply WAF rules, restrict administrative and internet-facing access, and monitor vendor advisories closely for forthcoming fixes.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation