2026-06-17
2026-06-17 10:40Z
HIGH

CVE-2026-35271 — Vulnerability: Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35271

Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Weblogic). Supported versions that are affected are 8.61 and 8.62. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT PeopleTools. While the vulnerability is in PeopleSoft Enterprise PT PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of thi CVSSv3.1 8.7 (HIGH)

VNDVulnerabilityTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-06-17
2026-06-17 10:40Z
CRIT

CVE-2026-35270 — Vulnerability: Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35270

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerabili CVSSv3.1 9.1 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-17
2026-06-17 10:40Z
CRIT

CVE-2026-35268 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35268

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Identity Manager. While the vulnerability is in Identity Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Id CVSSv3.1 9.9 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-17
2026-06-17 10:40Z
HIGH

CVE-2026-35267 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35267

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Identity Manager. Successful attacks of this vulnerability can result in takeover of Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: ( CVSSv3.1 8.8 (HIGH)

VNDVulnerabilityTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-17
2026-06-17 10:40Z
HIGH

CVE-2026-35265 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35265

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Identity Manager. Successful attacks of this vulnerability can result in takeover of Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1 CVSSv3.1 8.8 (HIGH)

VNDVulnerabilityTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-17
2026-06-17 10:40Z
CRIT

CVE-2026-35263 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35263

Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebLogic Server. While the vulnerability is in WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of WebLogic CVSSv3.1 9.9 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-17
2026-06-17 10:40Z
HIGH

CVE-2026-35262 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35262

Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Market Place). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Data Integrator. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Data Integrator accessible da CVSSv3.1 8.3 (HIGH)

VNDVulnerabilityTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-17
2026-06-17 10:40Z
HIGH

CVE-2026-35259 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise WebLogic

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35259

Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise WebLogic Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of WebLogic Server. CVSS 3.1 Base Score CVSSv3.1 8.8 (HIGH)

VNDVulnerabilityTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-17
2026-06-17 10:40Z
HIGH

CVE-2026-35258 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35258

Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise WebLogic Server. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in WebLogic Server, attacks may significantly impact additional products (s CVSSv3.1 8.7 (HIGH)

VNDVulnerabilityTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-06-17
2026-06-17 00:00Z
HIGH

AI in the underground: Curiosity, claims, and concerns

Sophos X-Ops·news.sophos.com

Sophos CTU researchers analyzed underground forum discussions revealing threat actors actively experimenting with generative AI for malware development, social engineering, data monetization, and intrusion operations. The research documents specific tools (Leak Bazaar, Apex AI, Metatron, PolyEngine, Cobalt Strike variants) being marketed with AI capabilities, alongside evidence of API key brokering, jailbreak techniques, and voice-bot fraud services. While many claims remain unvalidated, the data shows a clear shift in cybercriminal tradecraft toward AI-assisted workflows, though skepticism persists about job displacement and actual capability gains.

SRFApplicationTACTA0005TACTA0001TACTA0002SRFWebTACTA0003SWCobalt StrikeSWBruteratel
72
Edit Score
2026-06-17
2026-06-17 00:00Z
HIGH

Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign

Trend Micro Research·trendmicro.comin the wild

Trend Micro Research documented a sustained malvertising campaign (April–June 2026) targeting AI developers via Google Ads, initially using GitLab Pages subdomains to deliver ClickFix social engineering attacks impersonating Claude, ChatGPT, Perplexity, and other AI tools. The campaign escalated by pivoting to abuse Anthropic's claude.ai shared chat feature as a delivery mechanism for MacSync infostealer, affecting 2,000+ victims primarily in Asia-Pacific (67% of traffic, 30.5% from Taiwan), with the threat actors rotating 106+ malicious hostnames across six waves and evading traditional security controls by leveraging trusted domains.

TACTA0001TACTA0002SRFWebSRFCloudTACTA0009SWClaudeVNDGoogleVNDAnthropic
78
Edit Score
2026-06-16
2026-06-16 20:34Z
CRIT

CVE-2026-50751 | Check Point Security Gateway Improper Authentication Vulnerability

Horizon3.ai·horizon3.aiCVE-2026-50751in the wild

CVE-2026-50751 is a critical authentication bypass in Check Point Security Gateway affecting IKEv1-based Remote Access VPN and Mobile Access services. The vulnerability allows unauthenticated remote attackers to establish VPN sessions without valid credentials, with confirmed active exploitation in the wild since May 7, 2026, including at least one post-compromise case linked to Qilin ransomware affiliates. Check Point has released hotfixes for affected versions (R80.20.X through R82.10) and published indicators of compromise including malicious IP infrastructure.

TACTA0001SRFNetworkSRFNetwork ApplianceSWCheckpoint Security GatewayVNDCheckpointTYPVulnerabilitySTGInitial AccessTECT1133
92
Edit Score
2026-06-16
2026-06-16 20:16Z
CRIT

CVE-2026-22313 — By exploiting an OS command injection vulnerability an authenticated attacker can send arbitrary commands

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-22313

The device has a webserver that exposes a REST API authenticated with a token on the management network. By exploiting an OS command injection vulnerability an authenticated attacker can send arbitrary commands to the device that are executed with administrative permissions by the underlying operating system. CVSSv3.1 9.1 (CRITICAL)

CWECWE 78TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-16
2026-06-16 20:16Z
HIGH

CVE-2026-22312 — The device has a webserver that exposes a REST API authenticated with a constant

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-22312

The device has a webserver that exposes a REST API authenticated with a constant token. The unauthenticated API can be used by an attacker to get access to system settings, modify the configuration and execute some commands (e.g. system reboot). CVSSv3.1 8.6 (HIGH)

CWECWE 798TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-06-16
2026-06-16 20:16Z
HIGH

CVE-2026-0164 — Modem: In Modem, there is a possible out of bounds write due to a missing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-0164

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. CVSSv3.1 8.8 (HIGH)

CWECWE 120CWECWE 787VNDModemTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-16
2026-06-16 20:16Z
HIGH

CVE-2026-0162 — ParsePayloads: In ParsePayloads of AudioSdpParser.cpp, there is a possible memory corruption due to type confusion.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-0162

In ParsePayloads of AudioSdpParser.cpp, there is a possible memory corruption due to type confusion. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. CVSSv3.1 8.8 (HIGH)

CWECWE 843VNDParsepayloadsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-16
2026-06-16 20:16Z
HIGH

CVE-2026-0161 — RtpSession: In numberOfReportBlocks of RtpSession.cpp, there is a possible out of bounds write due to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-0161

In numberOfReportBlocks of RtpSession.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. CVSSv3.1 8.8 (HIGH)

CWECWE 787CWECWE 190VNDRtpsessionTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-16
2026-06-16 20:16Z
HIGH

CVE-2026-0160 — TextRtpPayloadDecoderNode: In TextRtpPayloadDecoderNode::DecodeT140 of TextRtpPayloadDecoderNode.cpp, there is a possible out of bounds write due to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-0160

In TextRtpPayloadDecoderNode::DecodeT140 of TextRtpPayloadDecoderNode.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. CVSSv3.1 8.8 (HIGH)

CWECWE 120VNDTextrtppayloaddecodernodeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-16
2026-06-16 20:16Z
HIGH

CVE-2026-0154 — Modem: In Modem, there is a possible way to trigger a modem crash during a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-0154

In Modem, there is a possible way to trigger a modem crash during a SIP REFER request due to memory corruption. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. CVSSv3.1 8.8 (HIGH)

CWECWE 120VNDModemTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-16
2026-06-16 20:16Z
HIGH

CVE-2026-0151 — IntfGraphCreate: In IntfGraphCreate of intfgraph.c, there is a possible out of bounds write due to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-0151

In IntfGraphCreate of intfgraph.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. CVSSv3.1 8.8 (HIGH)

CWECWE 787CWECWE 190VNDIntfgraphcreateTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-16
2026-06-16 20:16Z
HIGH

CVE-2026-0149 — RtpSession: In RtpSession::rtpSendRtcpPacket, there is a possible OOB write due to a heap buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-0149

In RtpSession::rtpSendRtcpPacket, there is a possible OOB write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. CVSSv3.1 8.8 (HIGH)

CWECWE 787CWECWE 122VNDRtpsessionTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-16
2026-06-16 20:16Z
HIGH

CVE-2026-0148 — VideoRtpPayloadDecoderNode: In multiple functions of VideoRtpPayloadDecoderNode.cpp, there is a possible out of bounds write due

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-0148

In multiple functions of VideoRtpPayloadDecoderNode.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. CVSSv3.1 8.8 (HIGH)

CWECWE 787CWECWE 190VNDVideortppayloaddecodernodeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-16
2026-06-16 20:16Z
HIGH

CVE-2026-0147 — In __mfc_core_nal_q_get_dec_metadata_sei_nal of mfc_core_nal_q.c, there is a possible out of bounds write due to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-0147

In __mfc_core_nal_q_get_dec_metadata_sei_nal of mfc_core_nal_q.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. CVSSv3.1 8.8 (HIGH)

CWECWE 120CWECWE 787TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-16
2026-06-16 20:16Z
HIGH

CVE-2026-0146 — In mfc_core_get_dec_metadata_sei_nal of mfc_core_reg_api.c, there is a possible out of bounds write due to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-0146

In mfc_core_get_dec_metadata_sei_nal of mfc_core_reg_api.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. CVSSv3.1 8.8 (HIGH)

CWECWE 120CWECWE 787TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-16
2026-06-16 20:16Z
HIGH

CVE-2026-0139 — Modem: In Modem, there is a possible out of bounds write due to a missing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-0139

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. CVSSv3.1 8.8 (HIGH)

CWECWE 119VNDModemTYPVulnerability
8.8
CVSS v3.1
94
Edit Score