Tuesday, June 23, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

AI and machine-learning infrastructure dominated yesterday's disclosures, with critical flaws in IBM Langflow, vLLM, BerriAI LiteLLM, and the expr-eval JavaScript library exposing model-serving and orchestration stacks to remote compromise. The brief covers 17 critical CVEs, up 325% from the prior day's 4, and 81 high-priority CVEs, up 326% from 19. Standouts include CVE-2026-10561 (CVSS 10) in IBM Langflow OSS, CVE-2026-12866 (CVSS 9.8) in expr-eval, and CVE-2026-49468 (CVSS 9.5) in BerriAI LiteLLM, while a cluster of MISP threat-intelligence platform issues (CVE-2026-56422, CVE-2026-56423, CVE-2026-56425) adds further exposure. Remote code execution and authentication weaknesses are the recurring patterns, affecting AI pipelines, collaboration tooling, and PHP-based document processing via PhpSpreadsheet. No vendor patches were available at disclosure, so teams should prioritize compensating controls and monitor advisories for fixes.

  • AI/ML tooling is the most affected category, with critical RCE-class flaws in IBM Langflow (CVE-2026-10561, CVSS 10), vLLM (CVE-2026-48746, CVSS 9.1), and BerriAI LiteLLM (CVE-2026-49468, CVSS 9.5)
  • 17 critical CVEs disclosed, a 325% increase from the prior day's 4
  • 81 high-priority CVEs disclosed, a 326% increase from the prior day's 19
  • Remote code execution and authentication bypass dominate, including expr-eval (CVE-2026-12866, CVSS 9.8) and a three-CVE MISP platform cluster (CVE-2026-56422/56423/56425)
  • Patch availability stands at 0% across disclosed CVEs, leaving mitigation and monitoring as the primary near-term defenses
  • 2 vulnerabilities are confirmed actively exploited, affecting Joomla Content Editor (CVE-2026-48907) and Splunk Enterprise/Cloud (CVE-2026-20253)

Immediate action: Prioritize AI/ML infrastructure running IBM Langflow, vLLM, and LiteLLM, along with MISP deployments and applications bundling the expr-eval and PhpSpreadsheet libraries, and apply network restrictions or access controls where direct fixes are unavailable. With patch availability at 0%, track vendor advisories closely and immediately address the actively exploited Joomla Content Editor and Splunk issues through available workarounds or upgrades.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation