Critical pre-authentication RCE in Splunk Enterprise with CVSS 9.8. Unauthenticated attackers can achieve remote code execution via arbitrary file creation and truncation in sidecar service. No authentication required, no workarounds available.
Patch Splunk Enterprise immediately to latest version. No mitigations or workarounds available. Isolate Splunk instances from untrusted networks. Audit logs for unauthorized access attempts prior to patching.
Source: Splunk • Published: 2026-06-10
Critical vulnerability in Qualcomm closed-source components affecting Android devices. One of three critical Qualcomm issues addressed in June 2026 Android security update. Affects vendor-specific implementations in Android devices.
Apply June 2026 Android security updates from device manufacturers. Contact Qualcomm-based device vendors for patch availability timelines. Consider device replacement for end-of-life devices unable to receive updates.
Source: Google • Published: 2026-06-17
Improper access control vulnerability in Widget Factory Joomla Content Editor added to CISA KEV catalog. Active exploitation confirmed. Allows unauthorized access to content management functions.
Federal agencies must remediate per CISA BOD timelines. Update Widget Factory Joomla Content Editor immediately. Review Joomla access logs for unauthorized modifications. Implement web application firewall rules to detect exploitation attempts.
Source: CISA • Published: 2026-06-17
Microsoft Defender zero-day vulnerability named 'RoguePlanet' disclosed by researcher Nightmare Eclipse. Tested against Windows 11 Official, Canary builds, and Windows 10 with June 2026 updates. Microsoft confirmed working on patch one week after disclosure.
Monitor for Microsoft security update release and apply immediately. Ensure Defender definition updates are current. Implement additional endpoint protection layers as compensating controls. Review endpoint logs for suspicious activity patterns indicative of exploitation.
Source: MSRC • Published: 2026-06-17
Collection of stealer logs from June 2026 added to HIBP containing 56M unique email addresses and 124M unique passwords across hundreds of millions of records. Passwords added to Pwned Passwords database for searchability.
Check email addresses at HaveIBeenPwned and change passwords immediately on all affected accounts. Enable 2FA wherever supported. Implement password manager with unique passwords per service. Deploy credential monitoring and threat intelligence feeds to detect compromised credentials in use.
Source: HaveIBeenPwned • Published: 2026-06-17
EU AI Act enforcement deadline August 2, 2026 activates high-risk AI compliance framework including Articles 8-15, Article 50 transparency requirements, and enforcement powers. Applies to AI in employment, credit decisions, education, and law enforcement. Penalties reach €15M or 3% global annual turnover.
Complete compliance gap assessments for all high-risk AI systems before August 2, 2026. Implement required risk assessment processes, technical documentation, human oversight mechanisms, and data governance frameworks. Establish AI governance committees and transparency mechanisms for AI-generated content. Engage legal counsel for compliance validation.
Source: European Commission • Published: 2026-08-02
AI-generated code security failure rate remains at 45% despite improvements in syntax correctness (95%). Java failure rates reach 70%+. Veracode 2026 State of Software Security shows 20% YoY increase in highly-exploitable and highly-severe security debt. Only 19% of organizations have full visibility into AI code usage while 97% actively use AI coding assistants.
Implement mandatory security scanning for all AI-generated code before production deployment. Deploy ASPM platforms for continuous security monitoring. Train developers on secure prompting techniques. Establish code review processes specifically for AI-introduced vulnerabilities. Use SAST/DAST tools calibrated for AI code patterns.
Source: Veracode • Published: 2026-06-17
CVE-2026-20253: Critical pre-authentication RCE in Splunk Enterprise with CVSS 9.8. Unauthenticated attackers can achieve remote code execution via arbitrary file creation and truncation in sidecar service. No authentication required, no workarounds available.