Tuesday, June 23, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

🎯 SSCV Profile

See how vulnerabilities affect your specific environment

CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework

Risk scores will be adjusted based on your selected environment

Archived Security Brief

AI and machine-learning infrastructure dominated yesterday's disclosures, with critical flaws in IBM Langflow, vLLM, BerriAI LiteLLM, and the expr-eval JavaScript library exposing model-serving and orchestration stacks to remote compromise. The brief covers 17 critical CVEs, up 325% from the prior day's 4, and 81 high-priority CVEs, up 326% from 19. Standouts include CVE-2026-10561 (CVSS 10) in IBM Langflow OSS, CVE-2026-12866 (CVSS 9.8) in expr-eval, and CVE-2026-49468 (CVSS 9.5) in BerriAI LiteLLM, while a cluster of MISP threat-intelligence platform issues (CVE-2026-56422, CVE-2026-56423, CVE-2026-56425) adds further exposure. Remote code execution and authentication weaknesses are the recurring patterns, affecting AI pipelines, collaboration tooling, and PHP-based document processing via PhpSpreadsheet. No vendor patches were available at disclosure, so teams should prioritize compensating controls and monitor advisories for fixes.

  • AI/ML tooling is the most affected category, with critical RCE-class flaws in IBM Langflow (CVE-2026-10561, CVSS 10), vLLM (CVE-2026-48746, CVSS 9.1), and BerriAI LiteLLM (CVE-2026-49468, CVSS 9.5)
  • 17 critical CVEs disclosed, a 325% increase from the prior day's 4
  • 81 high-priority CVEs disclosed, a 326% increase from the prior day's 19
  • Remote code execution and authentication bypass dominate, including expr-eval (CVE-2026-12866, CVSS 9.8) and a three-CVE MISP platform cluster (CVE-2026-56422/56423/56425)
  • Patch availability stands at 0% across disclosed CVEs, leaving mitigation and monitoring as the primary near-term defenses
  • 2 vulnerabilities are confirmed actively exploited, affecting Joomla Content Editor (CVE-2026-48907) and Splunk Enterprise/Cloud (CVE-2026-20253)

Immediate action: Prioritize AI/ML infrastructure running IBM Langflow, vLLM, and LiteLLM, along with MISP deployments and applications bundling the expr-eval and PhpSpreadsheet libraries, and apply network restrictions or access controls where direct fixes are unavailable. With patch availability at 0%, track vendor advisories closely and immediately address the actively exploited Joomla Content Editor and Splunk issues through available workarounds or upgrades.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation