CVE-2026-10520, CVE-2026-10523, CVE-2026-11645, CVE-2026-20245, CVE-2026-22732, CVE-2026-25089, CVE-2026-27671, CVE-2026-33017, CVE-2026-40128, CVE-2026-42897, CVE-2026-44748, CVE-2026-44815, CVE-2026-45586, CVE-2026-45657, CVE-2026-47291, CVE-2026-49160, CVE-2026-5027, CVE-2026-50507, CVE-2026-7473
Get tomorrow's brief in your inbox
Today: A new Windows zero-day exploit bypassing Microsoft Defender was released hours after Patch Tuesday, while Microsoft ships a record 206 patches including three public zero-days and critical RCE bugs. CISA adds three more actively exploited flaws to its KEV catalog, and attackers are exploiting a path traversal bug in the AI development platform Langflow.
New Windows Zero-Day Exploit 'RoguePlanet' Released
Security researcher Nightmare Eclipse released another Windows zero-day proof-of-concept exploit called RoguePlanet, targeting a race condition in Microsoft Defender that leads to local privilege escalation to SYSTEM. The exploit works on fully patched Windows 11 and Windows 10 machines with the June 2026 patches installed (tested on June 10, one day after Patch Tuesday). Multiple security researchers have validated that the exploit can spawn a command prompt with SYSTEM privileges on patched systems. The researcher states that Windows Server versions are vulnerable but the current proof-of-concept does not work on Server installations. The exploit was previously capable of remote code execution by tricking victims into opening .vhd(x) files on remote SMB shares, but Microsoft's May mitigations closed some attack paths, forcing the researcher to rework it.
'GreatXML' Zero-Day Exploit Bypasses BitLocker
Nightmare Eclipse released a second zero-day exploit within 24 hours, this one targeting BitLocker. The GreatXML exploit allows attackers with physical access to bypass BitLocker encryption and spawn a command prompt with SYSTEM privileges while in Recovery Mode. The vulnerability exists in Microsoft Defender's offline scan functionality. Any Windows system on which an offline scan was initiated at least once automatically becomes vulnerable. The exploit requires copying an XML file and a Recovery folder to the root of the computer's recovery partition, then rebooting into Recovery Mode. An attacker who has not previously initiated an offline scan can trigger it before executing the exploit, or boot directly into WinRE in offline scan state without logging in.
Microsoft Patches Exchange Server Zero-Day Exploited in Attacks (CVE-2026-42897)
Microsoft patched an actively exploited Exchange Server vulnerability that allows remote attackers to execute arbitrary JavaScript in cross-site scripting attacks targeting Outlook Web Access users. CVE-2026-42897 (CVSS 8.x, EPSS 7.9%, 92nd percentile) affects Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition. Exploitation requires sending a specially crafted email to a user who opens it in Outlook Web Access. Microsoft first released temporary mitigations through the Exchange Emergency Mitigation Service (EEMS) on May 14, and CISA added the vulnerability to its KEV catalog on May 15 with a May 29 patching deadline for federal agencies. Microsoft released permanent patches on June 9 and recommends keeping the EEMS mitigations in place for additional defense-in-depth protection. The company has not disclosed who is exploiting the vulnerability or who the targets are.
CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog
CISA added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog on June 10, with a June 23 patching deadline for federal agencies. CVE-2026-20245 (CVSS 7.8, EPSS 0.3%, 57th percentile) is an improper encoding vulnerability in Cisco Catalyst SD-WAN Manager allowing authenticated local attackers to execute arbitrary commands as root by supplying a crafted file. CVE-2026-11645 (CVSS 8.8, EPSS 5.5%, 90th percentile) is an out-of-bounds read and write in Google Chrome V8 allowing remote code execution inside a sandbox via crafted HTML pages. CVE-2026-7473 (CVSS 6.9, EPSS 22.5%, 96th percentile) is an incomplete comparison vulnerability in Arista Extensible Operating System (EOS) affecting 7020R, 7280R/R2, and 7500R/R2 series products configured as tunnel endpoints. Arista will not release patches due to risk of breaking existing configurations, instead providing ACL-based mitigations.
Path Traversal Flaw in AI Dev Platform Langflow Exploited in Attacks (CVE-2026-5027)
Attackers are actively exploiting CVE-2026-5027 (CVSS 8.8, EPSS 0%, 11th percentile), a high-severity path traversal vulnerability in Langflow, an open-source AI development platform with 149,000 GitHub stars. The flaw exists in the file upload functionality at the "POST /api/v2/files" endpoint, which fails to sanitize the filename parameter, allowing attackers to write files to arbitrary locations using path traversal sequences. Langflow enables unauthenticated auto-login by default, meaning no credentials are required to reach the vulnerable endpoint. A single unauthenticated request is sufficient to obtain a valid session token and proceed with exploitation. VulnCheck honeypots detected attackers dropping test files on vulnerable instances. Censys identified roughly 7,000 publicly exposed Langflow instances. Tenable disclosed the vulnerability on March 27, 2026, after attempting to contact Langflow maintainers three times in January and February without response. The issue was fixed in langflow-base version 0.8.3 and Langflow version 1.9.0.
Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugs
Microsoft's June 2026 Patch Tuesday is the largest on record with 206 security vulnerabilities addressed. Of these, 39 are rated Critical and 167 are Important. The breakdown includes 63 privilege escalation, 56 remote code execution, 30 information disclosure, 27 spoofing, 20 security feature bypass, seven denial-of-service, and three tampering vulnerabilities. The patches also include two non-Microsoft CVEs and more than 350 Chromium flaws addressed in Microsoft Edge. Three vulnerabilities were publicly disclosed at the time of release: CVE-2026-45586 (CVSS 7.8, EPSS 0.1%, 30th percentile) is a Windows CTFMON privilege escalation with a public proof-of-concept called GreenPlasma released by Nightmare Eclipse last month. CVE-2026-49160 (CVSS 7.5, EPSS 1.2%, 80th percentile) is an HTTP.sys denial-of-service related to the HTTP2/Bomb attack technique that can exhaust 64 GB RAM in 45 seconds. CVE-2026-50507 (CVSS 6.8, EPSS 0.1%, 27th percentile) is a BitLocker bypass dubbed bitskrieg that grants full access to encrypted data with physical access. Two critical remote code execution vulnerabilities require immediate attention: CVE-2026-45657 (CVSS 9.8) is a use-after-free in Windows Kernel allowing RCE via specially crafted network traffic with system-level privileges and no user interaction. CVE-2026-47291 (CVSS 9.8, EPSS 0.2%, 40th percentile) is an integer overflow in Windows HTTP.sys. CVE-2026-44815 (CVSS 9.8, EPSS 0.1%, 26th percentile) is a stack-based buffer overflow in Windows DHCP Client allowing unauthorized code execution over the network with no credentials or user action required.
Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities
Fortinet, Ivanti, and SAP released security updates addressing multiple critical vulnerabilities allowing arbitrary code execution and information disclosure. Fortinet patched CVE-2026-25089 (CVSS 9.1, EPSS 2.0%, 84th percentile), a command injection vulnerability in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS WEB UI allowing unauthenticated attackers to execute unauthorized commands via crafted HTTP requests. Affected versions: FortiSandbox 5.0.0 through 5.0.5 (upgrade to 5.0.6), FortiSandbox 4.4.0 through 4.4.8 (upgrade to 4.4.9), FortiSandbox Cloud 5.0.4 through 5.0.5 (upgrade to 5.0.6), and FortiSandbox PaaS 5.0.4 through 5.0.5 (upgrade to 5.0.6). Ivanti published fixes for two critical flaws in Ivanti Sentry (formerly MobileIron Sentry): CVE-2026-10520 (CVSS 10.0, EPSS 0.2%, 44th percentile) is an OS command injection allowing remote unauthenticated users to achieve root-level RCE, and CVE-2026-10523 (CVSS 9.9, EPSS 0.3%, 54th percentile) is an authentication bypass allowing remote unauthenticated attackers to create arbitrary administrative accounts. Both are fixed in versions R10.5.2, R10.6.2, and R10.7.1. SAP released four critical vulnerabilities in NetWeaver AS ABAP, ABAP Platform, Commerce Cloud, and Data Hub: CVE-2026-44748 (CVSS 9.9) is an XML signature wrapping vulnerability in SAML authentication, CVE-2026-27671 (CVSS 9.8, EPSS 0%, 13th percentile) is a memory corruption vulnerability allowing unauthenticated RCE via crafted RFC requests, CVE-2026-22732 (CVSS 9.1, EPSS 0%, 9th percentile) is a Spring security vulnerability, and CVE-2026-40128 (CVSS 9.0, EPSS 0.1%, 27th percentile) is a directory traversal vulnerability in NetWeaver Application Server Java.
Who Runs the Ransomware Group 'The Gentlemen?'
The Gentlemen ransomware group has become the second most active by victim count, claiming at least 332 victims since mid-2025 and more than 240 in 2026 alone, according to Check Point Software research. The group operates a ransomware-as-a-service model offering affiliates an aggressive 90/10 revenue split (compared to the industry standard 80/20), accelerating growth by attracting experienced operators from competing programs. The group targets internet-facing devices (VPNs, firewalls) as entry points and encrypts entire networks within hours. Check Point research indicates the administrator and primary operator uses the nickname Zeta88 on Russian-language cybercrime forums and was previously known as Hastalamuerte. A breach of the group's backend infrastructure revealed that Hastalamuerte/Zeta88 assembles the locker and RaaS panel, manages payments, and receives 10 percent of all ransoms. Intelligence firm Intel 471 shows Hastalamuerte registered on almost a dozen cybercrime forums between 2019 and present, including Exploit, Breachforums, Ramp_V2, BHF, Raidforums, and Nulled. Both Hastalamuerte and Zeta88 registered from Internet addresses in Izhevsk, Russia (capital of Udmurt Republic). Hastalamuerte registered on Raidforums in 2020 using the email [email protected] (1488 is a numeric symbol associated with white supremacy). Threat intelligence firm Constella Intelligence reports that the Hastalamuerte Telegram ID is connected to the Russian phone number 79127650004, which is assigned to Alexander Andreevich Yapaev, a 36-year-old from Izhevsk, according to records from hacked Russian government databases.
WA: Chelan County Enters Third Week of Disruptions with No Recovery Timeline
Chelan County, Washington entered its third week of system-wide disruptions on June 8 following a malware incident discovered over Memorial Day weekend. County officials have not provided a timeline for restoring affected systems. The county became aware of malware affecting the county network over the Memorial Day weekend.
Infostealers Turn Millions of Devices Into Credential Theft Machines
More than 11.1 million devices were infected with infostealers in 2025, with more than 3.3 billion credentials, browser artifacts, session information, and other identity data now circulating in illicit marketplaces, according to Flashpoint research. Infostealers have become the primary source of stolen credentials for attackers, providing authorized access to valuable data within target networks. More than 30 unique infostealer strains are active, available via malware-as-a-service for as little as $60 per month. During 2025, the most successful stealers were Lumma, Acreed, Rhadamanthys, Vidar, and StealC. During the first two months of 2026, Vidar rose from fourth place to dominate with more than 73% of all infected hosts, while Lumma dropped from number one in 2025 to just 1.1%. Stealers target credentials (website passwords, enterprise VPN/RDP/VNC, webmail, SaaS logins, cloud platform credentials, email accounts, password manager stores, autofill data), browser cookies, active session tokens, cloud/SaaS session artifacts, cryptocurrency wallet information (seeds, private keys), and credit card data. Stealers also gather system metadata (OS version, hardware, IP address) to provide context alongside stolen identity data. The most common delivery method is social engineering attacks against users with desktops or laptops, with statistical near-certainty of success somewhere in the target environment.
Deceptive Installers: How Fake Apps Target macOS
Deceptive installers and weaponized disk images have become the dominant delivery mechanism for macOS malware. In 2025, over 65% of newly reported macOS malware was classified as infostealers, focused on credential and data theft. The vast majority of macOS infostealers do not establish persistence mechanisms like LaunchAgents or LaunchDaemons. Instead, they operate as smash-and-grab attacks that land on the machine, harvest saved passwords, browser cookies, authentication tokens, and cryptocurrency wallets, then exfiltrate the data to C2 servers before detection. The infection chain typically starts with search engine optimization (SEO) poisoning to hijack search results, or compromised links on torrent networks and cracked software forums. Attackers prefer .dmg disk images over .pkg packages because packages require formal developer signing and face rigid macOS security scrutiny, while disk images provide a path of least resistance. When users double-click a DMG, macOS mounts it as a virtual drive in /Volumes, isolated from system files. Attackers defeat Gatekeeper (Apple's digital signing verification) through social engineering rather than code exploits, tricking users into manually overriding security controls.
GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks
GitHub announced breaking changes coming to npm version 12 (scheduled for release next month) that will disable install scripts by default to combat software supply chain threats. Install-time lifecycle scripts are the single largest code-execution surface in the npm ecosystem because "npm install" runs scripts from every transitive dependency, allowing a single compromised package anywhere in the dependency tree to run arbitrary code on developer machines or CI runners. The changes require explicit user approval before code execution during "npm install" instead of trusting dependencies by default. Specific changes: npm install will no longer execute preinstall, install, or postinstall scripts from dependencies unless explicitly allowed. npm install will no longer resolve Git dependencies (direct or transitive) unless explicitly allowed via --allow-git. npm install will no longer resolve dependencies from remote URLs (https tarballs) unless explicitly allowed via --allow-remote. Native node-gyp builds are also blocked by default because npm runs an implicit node-gyp rebuild even without an explicit install script. Defaulting --allow-git to "none" closes a code execution path where a Git dependency's .npmrc configuration file could override the Git executable, even with --ignore-scripts.
Microsoft Fixes BitLocker Recovery Bug on Windows Server 2025
Microsoft resolved a known issue causing some Windows Server 2025 devices to boot into BitLocker recovery after installing the April 2026 security update. The issue only affects devices with an unrecommended BitLocker Group Policy configuration where all the following conditions are met: BitLocker is enabled on the OS drive, the Group Policy "Configure TPM platform validation profile for native UEFI firmware configurations" is configured with PCR7 included (or the equivalent registry key is set manually), System Information reports that the Secure Boot State PCR7 Binding is "Not Possible", the Windows UEFI CA 2023 certificate is present in the device's Secure Boot Signature Database making it eligible for the 2023-signed Windows Boot Manager, and the device is not already running the 2023-signed Windows Boot Manager. The fix is included in the KB5094125 (Windows Server 2025) and KB5093998 (Windows 11 23H2) cumulative updates released during June Patch Tuesday. To prevent the unexpected BitLocker recovery key prompt, devices with incompatible group policy configurations are prevented from installing the 2023-signed Windows Boot Manager. Event ID 1032 appears in the System event log when this occurs.
Microsoft: Some Windows PCs Fail to Install Latest Monthly Updates
Microsoft warned that a small percentage of Windows 10 (versions 22H2 and 21H2) and Windows 11 (version 23H2) devices upgraded to Windows 11 version 24H2 or 25H2 may fail to install the latest cumulative update. Affected users see 0x80073712 or 0x800f0993 errors when trying to install June 2026 cumulative updates. Windows Update log files show error 0x800f0993 (PSFX_E_REBASE_HYDRATION_CANDIDATES_MISSING) or 0x80073712 (ERROR_SXS_COMPONENT_STORE_CORRUPT). Microsoft says a fix will roll out automatically to unmanaged enterprise devices and personal PCs (Home edition) following a system restart, with no new devices affected starting May 19, 2026. For affected devices already upgraded to Windows 11 24H2 or 25H2, users should remove the affected package by running "dism /online /remove-package /packagename:Package_for_RollupFix~31bf3856ad364e35~amd64~~26100.1742.1.10" in an elevated Command Prompt. If this does not fix the issue, perform a Windows 11 in-place upgrade.
The combination of two unpatched Windows zero-days released hours after a record-breaking Patch Tuesday demonstrates the escalating tension between Microsoft and security researchers over vulnerability disclosure. The researcher Nightmare Eclipse has now released seven zero-day exploits (BlueHammer, RedSun, UnDefend, GreenPlasma, YellowKey, RoguePlanet, and GreatXML) after expressing discontent with Microsoft's vulnerability disclosure process. Meanwhile, the surge in infostealer infections (11.1 million devices in 2025) and the active exploitation of AI development platforms like Langflow highlight how attackers are shifting focus from traditional exploitation to credential theft and supply chain compromise as more efficient attack paths.