CVE-2026-8451 (CVSS 8.8): pre-auth flaw lets attackers leak Citrix NetScaler memory via crafted SAML requests. No confirmed exploitation yet — patch now.
CVE-2026-8037 (CVSS 9.8) is a pre-auth RCE in Progress Kemp LoadMaster under active exploitation attempts. Patch to 7.2.63.2 / 7.2.54.18 now.
CVE-2026-48558: CVSS 10.0 SimpleHelp OIDC auth bypass exploited to deploy TaskWeaver and Djinn Stealer malware. Patch to 5.5.16 now — CISA deadline 2 July 2026.
CVE-2026-42530 is a CVSS 9.2 critical use-after-free in NGINX’s HTTP/3 module enabling DoS and potential RCE. Upgrade to NGINX 1.31.2 or 1.30.3 now.
CVE-2026-47291 is a CVSS 9.8 unauthenticated RCE in Windows HTTP.sys affecting every supported Windows version. Apply the June 2026 Patch Tuesday update now.
CVE-2026-12569 is a CVSS 9.3 unauthenticated RCE in PTC Windchill & FlexPLM, exploited in the wild to drop JSP web shells and on CISA KEV. Patch via PTC CS473270 now.
CVE-2025-67038 is a CVSS 9.8 unauthenticated root command injection in Lantronix EDS5000 console servers, now in CISA KEV and exploited in the wild. Patch firmware 2.2.0.0R1 now.
CVE-2026-35273 is a CVSS 9.8 unauthenticated SSRF-to-RCE in Oracle PeopleSoft PeopleTools, exploited as a zero-day by ShinyHunters and on CISA KEV. Patch via CPU187 and hunt for compromise now.
CVE-2026-34908 is a CVSS 10.0 access-control flaw in Ubiquiti UniFi OS, now in CISA KEV and exploited in the wild. Patch UniFi OS Server 5.0.8+ and firmware 5.1.12+ now.
CVE-2026-20253 is a CVSS 9.8 unauthenticated RCE in Splunk Enterprise, now in CISA KEV and exploited in the wild. Patch to 10.0.7 or 10.2.4 now.
Writing on the Wall is a newsletter for freelance writers seeking inspiration, advice, and support on their creative journey.