Tuesday, June 30, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Tuesday's disclosures center on cloud and database infrastructure, with critical flaws in AWS Application Load Balancer and Amazon CloudFront (both CVSS 9.8), Google's MCP Toolbox for Databases (CVSS 9.3), and SUSE Rancher (CVSS 9.4). Twelve critical CVEs were disclosed alongside 69 high-priority issues, up sharply from zero critical and 24 high the prior day. Notable named vulnerabilities include CVE-2026-13763 and CVE-2026-13762 in AWS edge and load-balancing services, CVE-2026-56290 (CVSS 10) in JoomlaCK Page Builder CK, and CVE-2026-11720 in Google's MCP Toolbox for Databases. The activity spans cloud delivery networks, web application builders, and database tooling, with several flaws enabling remote exploitation against internet-facing services. No vendor patches were reflected in the data at disclosure time, so teams should prioritize compensating controls and monitor vendor advisories for fixes.

  • AWS Application Load Balancer (CVE-2026-13763) and Amazon CloudFront (CVE-2026-13762) both carry CVSS 9.8, exposing widely-used cloud edge and load-balancing infrastructure
  • 12 critical CVEs disclosed, up from 0 the prior day
  • 69 high-priority CVEs disclosed, a 188% increase from 24 the prior day
  • Remote exploitation patterns dominate, affecting cloud delivery (CloudFront), database tooling (Google MCP Toolbox), and web builders (JoomlaCK Page Builder CK, CVSS 10)
  • Patch availability stands at 0% across the disclosed set, leaving critical cloud and CMS components without vendor fixes at disclosure
  • 7 vulnerabilities have confirmed active exploitation, including Ubiquiti UniFi OS, Cisco Unified CM, and SimpleHelp

Immediate action: Prioritize AWS-hosted environments using Application Load Balancer and CloudFront (CVE-2026-13763, CVE-2026-13762), along with Google MCP Toolbox for Databases, SUSE Rancher, and JoomlaCK-based sites, for immediate review and isolation. With no patches available at disclosure, apply network restrictions and access controls to internet-facing instances and monitor vendor channels for forthcoming fixes. Separately, organizations running Ubiquiti UniFi OS, Cisco Unified CM, PTC Windchill/FlexPLM, or SimpleHelp should address the seven actively exploited vulnerabilities without delay.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation