Oracle PeopleSoft CVE-2026-35273: ShinyHunters Zero-Day RCE Under Active Exploit | June 2026
June 11, 2026 Oracle has issued an emergency security alert for CVE-2026-35273, a critical zero-day vulnerability in PeopleSoft Enterprise PeopleTools that enables unauthenticated remote code execution. The ShinyHunters extortion gang is actively…
Ivanti Sentry CVE Root RCE Under Active Exploit
June 11, 2026 Attackers are actively exploiting CVE-2026-10520, a maximum-severity vulnerability in Ivanti Sentry that allows unauthenticated root remote code execution on exposed secure mobile gateways. The flaw was patched on June 9, 2026, but threat…
Proto6: Six protobuf.js Vulnerabilities Expose Node.js Apps to RCE and DoS
June 10, 2026 Cybersecurity researchers at Cyera have disclosed six vulnerabilities — collectively codenamed Proto6 — in protobuf.js, a widely deployed JavaScript and TypeScript implementation of Google’s Protocol Buffers data serialization format.…
LiteLLM CVE-2026-42271: CISA KEV Alert for Active Command Injection Exploit
June 9, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a high-severity command injection flaw in BerriAI LiteLLM to its Known Exploited Vulnerabilities (KEV) catalog on Monday. The vulnerability, tracked as CVE-2026-42271,…
Google Chrome Zero-Day CVE-2026-11645: Fifth 2026 Exploit
June 9, 2026 Google has released an emergency security update for Chrome to fix CVE-2026-11645, a high-severity zero-day vulnerability in the V8 JavaScript engine that is already being exploited in the wild. Consequently, this marks the fifth actively…
Check Point VPN Zero-Day CVE-2026-50751: Qilin Ransomware Exploit
June 8, 2026 Check Point has disclosed a critical zero-day vulnerability in its Remote Access VPN and Mobile Access deployments that allows unauthenticated attackers to bypass authentication and establish VPN connections. The flaw, tracked as…
AI Agent Discovers 21 FFmpeg Zero-Days: CVE-2026-39210-39218
June 6, 2026 An autonomous AI security agent has uncovered 21 zero-day vulnerabilities in FFmpeg, the ubiquitous media processing library that powers browsers, streaming platforms, and countless applications worldwide. The findings mark a significant…
Cisco Unified CM CVE-2026-20230: Critical SSRF Flaw With Public PoC
June 04, 2026 Cisco has disclosed a critical server-side request forgery (SSRF) vulnerability in its Unified Communications Manager platform. The flaw, tracked as CVE-2026-20230, could allow unauthenticated remote attackers to gain root privileges on…
CVE-2026-23479: AI Discovers 2-Year-Old Redis RCE Vulnerability
June 3, 2026 Redis has patched a critical use-after-free vulnerability that allows authenticated attackers to execute arbitrary operating system commands on the database server. The flaw, tracked as CVE-2026-23479, was discovered by an autonomous AI…
CVE-2025-48595 Android Zero-Day Under Active Exploit
June 02, 2026 Google has released the June 2026 Android security update, patching 124 vulnerabilities across the mobile operating system. One high-severity flaw in the Android Framework component, tracked as CVE-2025-48595, is already under active…