Amazon Q Developer CVE Malicious MCP Configs Steal Cloud Credentials
June 26, 2026 A high-severity vulnerability in Amazon Q Developer could allow malicious repositories to run arbitrary commands and steal a developer’s cloud credentials. The flaw, tracked as CVE-2026-12957 with a CVSS score of 8.5, was disclosed by…
Cisco Unified CM CVE-2026-20230: Active Exploitation Confirmed
June 24, 2026 A critical server-side request forgery vulnerability in Cisco Unified Communications Manager is now under active exploitation in the wild. Threat intelligence firm Defused confirmed attacks against CVE-2026-20230 over the weekend, marking a…
Squidbleed CVE-2026-47729: 29-Year Squid Proxy Bug Leaks HTTP Credentials
June 22, 2026 Researchers disclosed a critical heap over-read vulnerability in Squid Proxy that has existed since 1997. CVE-2026-47729, nicknamed Squidbleed, lets a trusted attacker on the same proxy leak another user’s cleartext HTTP requests.…
AryStinger Botnet Hijacks 4,300 D-Link Routers for Global Proxy Network
June 22, 2026 A previously undocumented malware botnet named AryStinger has compromised more than 4,300 outdated routers worldwide. Unlike typical IoT botnets built for DDoS or cryptocurrency mining, this threat converts infected devices into distributed…
Gravity SMTP CVE-2026-4020: WordPress Plugin Actively Exploited
June 20, 2026 Threat actors are actively exploiting CVE-2026-4020, an unauthenticated information disclosure vulnerability in the popular Gravity SMTP WordPress plugin. This flaw exposes sensitive credentials and system configuration data on over 100,000…
Splunk Enterprise CVE-2026-20253: CISA KEV Alert Orders Federal Patch by Sunday
June 19, 2026 CISA has added a critical Splunk Enterprise vulnerability to its Known Exploited Vulnerabilities catalog after threat actors began actively exploiting it in the wild. Tracked as CVE-2026-20253, the flaw allows unauthenticated remote…
F5 Critical NGINX RCE CVE-2026-42530 and CVE-2026-42055 Patched
June 18, 2026 Cybersecurity company F5 has released out-of-band security updates for multiple critical NGINX vulnerabilities. Consequently, organizations running NGINX Plus, NGINX Open Source, or NGINX Gateway Fabric should prioritize patching…
CISA Orders Federal Patch for Joomla JCE CVE-2026-48907 by Friday
June 18, 2026 CISA has added a maximum-severity vulnerability in the Widget Factory Joomla Content Editor (JCE) to its Known Exploited Vulnerabilities catalog. The flaw, tracked as CVE-2026-48907, allows unauthenticated attackers to upload and execute…
Three FortiSandbox CVEs Under Active Exploit: Unauthenticated RCE
June 16, 2026 Threat actors are actively exploiting three critical vulnerabilities in Fortinet’s FortiSandbox threat detection platform. The flaws, tracked as CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089, allow unauthenticated remote…
Cisco SD-WAN Zero-Day CVE-2026-20262: Active Root Exploit
June 15, 2026 Cisco has patched a critical zero-day vulnerability in its Catalyst SD-WAN Manager platform. The flaw, tracked as CVE-2026-20262, allows authenticated remote attackers to overwrite files and escalate to root privileges. CISA added the…