Friday, June 26, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Friday's disclosures center on developer and infrastructure platforms, led by two CVSS 10 vulnerabilities in Apache Kvrocks (CVE-2026-46752) and Flowise (CVE-2025-71338), alongside critical flaws in Cursor, Dell Wyse Management Suite, and ToolJet. The brief includes 25 critical CVEs, up 4% from the prior day's 24, and 42 high-priority CVEs, down 35% from 65. Dell Wyse Management Suite (CVE-2026-41120, CVSS 9.8) and the paired Cursor IDE vulnerabilities (CVE-2026-50548 and CVE-2026-50549, CVSS 9.3) extend exposure into endpoint management and developer workstations. Remote code execution and authentication bypass dominate the critical set, with affected products spanning data stores, low-code platforms, IoT/camera systems from GeoVision, and edge networking. Vendor patch availability is currently reported at 0%, so organizations should prioritize compensating controls, network segmentation, and access restrictions for exposed instances.

  • Apache Kvrocks (CVE-2026-46752) and Flowise (CVE-2025-71338) both carry CVSS 10 scores, the most severe items in today's set
  • Critical CVEs reached 25, up 4% from 24 the prior day
  • High-priority CVEs fell to 42, down 35% from 65 the prior day
  • Remote code execution and authentication bypass patterns affect Cursor IDE, Dell Wyse Management Suite, ToolJet, and GeoVision camera systems
  • Patch availability stands at 0%, requiring compensating controls for exposed Apache Kvrocks, Flowise, and Dell management systems
  • Six vulnerabilities show active exploitation, including Ubiquiti UniFi OS, Cisco Unified CM, and Lantronix EDS5000

Immediate action: Prioritize Apache Kvrocks, Flowise, Dell Wyse Management Suite, and Cursor IDE deployments, restricting network access to these services and isolating developer and management systems until fixes ship. With patch availability at 0% for critical issues, apply segmentation, authentication hardening, and monitoring as interim mitigations, and accelerate remediation for the actively exploited Ubiquiti UniFi OS, Cisco Unified CM, and PTC Windchill vulnerabilities.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation