Saturday, June 27, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

🎯 SSCV Profile

See how vulnerabilities affect your specific environment

CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework

Risk scores will be adjusted based on your selected environment

Archived Security Brief

Saturday's disclosures concentrate on open-source web platforms and developer tooling, with maximum-severity flaws in Budibase, Kestra, and OpenProject leading the set. The brief covers 31 critical CVEs, up 24% from the prior day's 25, and 60 high-priority CVEs, a 43% increase from 42. CVE-2026-54350 (CVSS 10) in Budibase and CVE-2026-53576 and CVE-2026-49869 (both CVSS 10) in Kestra represent unauthenticated remote code execution risks, while CVE-2026-46386 (CVSS 9.9) and CVE-2026-52780 (CVSS 9.6) affect OpenProject. WordPress ecosystem plugins including BuddyBoss and Uncanny Automator Pro add further critical exposure, and six CVEs across Ubiquiti UniFi OS, Cisco Unified CM, PTC Windchill, and Lantronix EDS5000 carry confirmed exploitation. Vendor patches were not yet reflected at disclosure time, so teams should prioritize compensating controls and monitor vendor advisories for fixes on internet-facing deployments.

  • Budibase and Kestra anchor today's critical set with CVSS 10 remote code execution flaws (CVE-2026-54350, CVE-2026-53576, CVE-2026-49869)
  • Critical CVEs rose 24% to 31, up from 25 the prior day
  • High-priority CVEs rose 43% to 60, up from 42 the prior day
  • Unauthenticated RCE and authorization-bypass patterns dominate, affecting OpenProject (CVE-2026-46386), Invoice Generator (CVE-2026-12415), and mise (CVE-2026-33646)
  • Patches were not yet available at disclosure across the critical set, leaving internet-facing self-hosted platforms exposed
  • Six actively exploited CVEs span Ubiquiti UniFi OS, Cisco Unified CM, PTC Windchill, and Lantronix EDS5000

Immediate action: Prioritize self-hosted web platforms — Budibase, Kestra, and OpenProject — along with WordPress sites running BuddyBoss or Uncanny Automator Pro, and the actively exploited Ubiquiti UniFi OS and Cisco Unified CM deployments. With vendor fixes not yet reflected for the critical issues, restrict external access, apply available workarounds, and watch vendor advisories so patches can be deployed as soon as they ship.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation