Saturday, June 27, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Saturday's disclosures concentrate on open-source web platforms and developer tooling, with maximum-severity flaws in Budibase, Kestra, and OpenProject leading the set. The brief covers 31 critical CVEs, up 24% from the prior day's 25, and 60 high-priority CVEs, a 43% increase from 42. CVE-2026-54350 (CVSS 10) in Budibase and CVE-2026-53576 and CVE-2026-49869 (both CVSS 10) in Kestra represent unauthenticated remote code execution risks, while CVE-2026-46386 (CVSS 9.9) and CVE-2026-52780 (CVSS 9.6) affect OpenProject. WordPress ecosystem plugins including BuddyBoss and Uncanny Automator Pro add further critical exposure, and six CVEs across Ubiquiti UniFi OS, Cisco Unified CM, PTC Windchill, and Lantronix EDS5000 carry confirmed exploitation. Vendor patches were not yet reflected at disclosure time, so teams should prioritize compensating controls and monitor vendor advisories for fixes on internet-facing deployments.

  • Budibase and Kestra anchor today's critical set with CVSS 10 remote code execution flaws (CVE-2026-54350, CVE-2026-53576, CVE-2026-49869)
  • Critical CVEs rose 24% to 31, up from 25 the prior day
  • High-priority CVEs rose 43% to 60, up from 42 the prior day
  • Unauthenticated RCE and authorization-bypass patterns dominate, affecting OpenProject (CVE-2026-46386), Invoice Generator (CVE-2026-12415), and mise (CVE-2026-33646)
  • Patches were not yet available at disclosure across the critical set, leaving internet-facing self-hosted platforms exposed
  • Six actively exploited CVEs span Ubiquiti UniFi OS, Cisco Unified CM, PTC Windchill, and Lantronix EDS5000

Immediate action: Prioritize self-hosted web platforms — Budibase, Kestra, and OpenProject — along with WordPress sites running BuddyBoss or Uncanny Automator Pro, and the actively exploited Ubiquiti UniFi OS and Cisco Unified CM deployments. With vendor fixes not yet reflected for the critical issues, restrict external access, apply available workarounds, and watch vendor advisories so patches can be deployed as soon as they ship.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation