Back to trending CVEs

Week of June 22, 2026

Trending* CVEs over the last 7 days (from June 15, 2026 to June 22, 2026)

1
CVE-2026-20253Splunk / Splunk
KEV
SYRN Score97
CVSS9.8
Activity64
Published06/10/2026
StatusHighly Active

In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials. Splunk Enterprise versions 9.4 and earlier are not affected. If you cannot immediately upgrade to a fixed version, you can mitigate this vulnerability by disabling the PostgreSQL sidecar service.

2
CVE-2026-20262Cisco Systems / Catalyst Sd-Wan Manager
NewKEV
SYRN Score94
CVSS6.5
Activity53
Published06/15/2026
StatusHighly Active

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This vulnerability exists because the affected software does not properly validate user-supplied input during a file upload process. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected API endpoint of the affected system. A successful exploit could allow the attacker to create or overwrite any file on the underlying operating system. This file could later be used to elevate to root. To exploit this vulnerability, the attacker must have valid credentials with at least a lower-privileged, single-task user account.

3
CVE-2026-48907Joomlacontenteditor.net / Joomla Content Editor (Jce) Extension For Joomla
KEV
SYRN Score96
CVSS10.0
Activity48
Published06/05/2026
StatusHighly Active

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.

4
CVE-2026-50656Microsoft / Cisco Identity Services Engine
New
SYRN Score57
CVSS7.8
Activity43
Published06/16/2026
StatusHighly Active

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.

5
CVE-2026-35273Oracle / Peoplesoft
KEVRansomware
SYRN Score97
CVSS9.8
Activity28
Published06/11/2026
StatusHighly Active

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

6
CVE-2026-50751Checkpoint / Gaia Embedded
KEV
SYRN Score96
CVSS9.3
Activity26
Published06/08/2026
StatusHighly Active

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

7
CVE-2026-54420Litespeedtech / Litespeed Cpanel Plugin
KEV
SYRN Score93
CVSS8.5
Activity26
Published06/14/2026
StatusHighly Active

LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026.

8
CVE-2026-4020Rocketgenius / Gravity Smtp
SYRN Score89
CVSS7.5
Activity26
Published03/31/2026
StatusHighly Active

The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4. This is due to a REST API endpoint registered at /wp-json/gravitysmtp/v1/tests/mock-data with a permission_callback that unconditionally returns true, allowing any unauthenticated visitor to access it. When the ?page=gravitysmtp-settings query parameter is appended, the plugin's register_connector_data() method populates internal connector data, causing the endpoint to return approximately 365 KB of JSON containing the full System Report. This makes it possible for unauthenticated attackers to retrieve detailed system configuration data including PHP version, loaded extensions, web server version, document root path, database server type and version, WordPress version, all active plugins with versions, active theme, WordPress configuration details, database table names, and any API keys/tokens configured in the plugin.

9
CVE-2026-42530F5 / Nginx Open Source
New
SYRN Score62
CVSS8.1
Activity23
Published06/17/2026
StatusActive

NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a Use-after-Free in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

10
CVE-2026-39813Fortinet / Fortisandbox
SYRN Score93
CVSS9.1
Activity20
Published04/14/2026
StatusActive

A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via specially crafted HTTP requests.

* Trending is based on the number of sightings collected from SYRN's threat intelligence sources over the given period.

Monitor these vulnerabilities and get alerted when new threats target your stack.

Get Started Free