Security Digest: June 11, 2026 - 11 Critical Vulnerabilities

Today’s urgent risk is a mix of internet-reachable takeover bugs, authentication bypasses, and high-impact Spring framework flaws that can expose sensitive data, weaken security controls, or lead to remote code execution. The most dangerous issues are CVE-2026-35273 in Oracle PeopleSoft, CVE-2026-10795 in UpdraftPlus, and multiple Spring Web Services and Spring for GraphQL vulnerabilities that should be patched immediately.

· 10 min read

Executive Summary

Today’s urgent risk is a mix of internet-reachable takeover bugs, authentication bypasses, and high-impact Spring framework flaws that can expose sensitive data, weaken security controls, or lead to remote code execution. The most dangerous issues are CVE-2026-35273 in Oracle PeopleSoft, CVE-2026-10795 in UpdraftPlus, and multiple Spring Web Services and Spring for GraphQL vulnerabilities that should be patched immediately.

If you run any affected Oracle, Spring, WordPress, vLLM, or integration workloads, prioritize patching today, disable exposed features where possible, and assume public-facing services are at risk until verified clean.

Critical Vulnerabilities

  • CVE-2026-35273: Oracle PeopleSoft PeopleTools takeover
    • Impact: Unauthenticated attackers can compromise PeopleSoft Enterprise PeopleTools over HTTP and potentially take over the platform.
    • Affected Systems: Oracle PeopleSoft Enterprise PeopleTools 8.61 and 8.62.
    • Immediate Action: Patch immediately. If you cannot patch today, restrict network access to PeopleSoft endpoints to trusted admin networks only.
    • Mitigation: Apply Oracle’s fix as soon as it is available; place PeopleSoft behind VPN or allowlists until remediated.
  • CVE-2026-40999: Spring WS outbound connection abuse
    • Impact: Attackers can steer outbound connections to attacker-chosen destinations, enabling SSRF-style abuse and potential internal exposure.
    • Affected Systems: Spring Web Services 5.0.0-5.0.1, 4.1.0-4.1.3, 4.0.0-4.0.18, 3.1.0-3.1.8.
    • Immediate Action: Upgrade Spring Web Services now; block unexpected outbound traffic from application servers.
    • Mitigation: Patch to a fixed release and validate any WS-Addressing use of ReplyTo or FaultTo.
  • CVE-2026-40994: Spring WS WS-Security validation weakened
    • Impact: Services may accept SOAP security messages that should be rejected, weakening protocol enforcement and trust checks.
    • Affected Systems: Spring Web Services 5.0.0-5.0.1, 4.1.0-4.1.3, 4.0.0-4.0.18, 3.1.0-3.1.8.
    • Immediate Action: Patch immediately and review any service relying on WS-Security for access control.
    • Mitigation: Update to the vendor-fixed version; temporarily reduce exposure of SOAP endpoints if patching is delayed.
  • CVE-2026-40998: Spring WS XML parsing exposes XXE risk
    • Impact: Attackers can exploit untrusted XML processing to read local files or trigger other XML entity attacks.
    • Affected Systems: Spring Web Services 5.0.0-5.0.1, 4.1.0-4.1.3, 4.0.0-4.0.18, 3.1.0-3.1.8.
    • Immediate Action: Patch now; stop accepting untrusted XML payloads where possible.
    • Mitigation: Upgrade and ensure XML parsers reject external entities and DTDs.
  • CVE-2026-41700: Spring for GraphQL WebSocket hijacking
    • Impact: A malicious site can use a victim’s browser session to run GraphQL operations as that user.
    • Affected Systems: Spring for GraphQL 2.0.0-2.0.3, 1.4.0-1.4.5, 1.3.0-1.3.8, 1.0.0-1.0.6.
    • Immediate Action: Disable WebSocket transport if not required; patch immediately if it is enabled.
    • Mitigation: Apply the fixed release and enforce origin checks and session protections.
  • CVE-2026-10795: UpdraftPlus authentication bypass to admin-level RCE
    • Impact: Unauthenticated attackers can forge RPC commands, act as an administrator, and potentially install malicious plugins for remote code execution.
    • Affected Systems: UpdraftPlus: WP Backup & Migration Plugin up to and including 1.26.4.
    • Immediate Action: Update immediately; if exposed, assume compromise risk and review admin/plugin activity.
    • Mitigation: Install the patched version, rotate WordPress admin credentials, and inspect for unauthorized plugins or scheduled tasks.
  • CVE-2026-41699: Spring for GraphQL unsafe deserialization
    • Impact: A crafted GraphQL request may lead to remote code execution on systems with vulnerable classpath conditions.
    • Affected Systems: Spring for GraphQL 2.0.0-2.0.3, 1.4.0-1.4.5, 1.3.0-1.3.8.
    • Immediate Action: Patch now and review any exposed paginated GraphQL endpoints.
    • Mitigation: Upgrade and remove unnecessary deserialization-capable classes from the runtime where feasible.
  • CVE-2026-5497: vLLM video data URL memory exhaustion
    • Impact: A single unauthenticated API request can trigger out-of-memory crashes and denial of service.
    • Affected Systems: vLLM 0.8.0 and later.
    • Immediate Action: Rate-limit or disable video data URL handling and patch as soon as a fix is available.
    • Mitigation: Restrict OpenAI-compatible API exposure and cap request sizes until remediated.
  • CVE-2026-41856: Spring for GraphQL authorization checks may be skipped
    • Impact: Security annotations on controller data fetchers may be ignored, allowing unauthorized access to protected operations.
    • Affected Systems: Spring for GraphQL 2.0.0-2.0.3, 1.4.0-1.4.5, 1.3.0-1.3.8, 1.0.0-1.0.6.
    • Immediate Action: Patch immediately and manually verify authorization on all GraphQL controller methods.
    • Mitigation: Upgrade and add defense-in-depth checks at the service layer.
  • CVE-2023-33999: WP Mail Log DOM XSS
    • Impact: Attackers can execute script in the browser of an admin or logged-in user.
    • Affected Systems: WP Mail Log up to 1.0.2.
    • Immediate Action: Remove or update the plugin immediately; treat exposed admin sessions as high risk.
    • Mitigation: Patch to a fixed release and clear browser sessions for privileged users.
  • CVE-2026-40987: Spring Integration arbitrary file write
    • Impact: A malicious or compromised FTP/SFTP/SMB server can write attacker-controlled files anywhere on the client filesystem.
    • Affected Systems: Spring Integration 7.0.0-7.0.4, 6.5.0-6.5.8, 6.4.0-6.4.11, 6.3.0-6.3.14, 5.5.0-5.5.20.
    • Immediate Action: Patch now and disconnect untrusted remote file endpoints immediately.
    • Mitigation: Upgrade to the fixed release and restrict remote file transfer sources to trusted servers only.

What to Do Now

  1. Patch the highest-risk internet-facing systems first: Oracle PeopleSoft, UpdraftPlus, Spring Web Services, Spring for GraphQL, Spring Integration, and vLLM.
  2. Disable risky features temporarily: WebSocket transport, untrusted XML handling, remote file transfers, and any public API paths not strictly required.
  3. Restrict network exposure: Put admin consoles behind VPN/allowlists and block unexpected outbound connections from application servers.
  4. Verify versions immediately against the affected ranges listed above.
  5. Assume compromise if exposed: Review logs for unusual admin actions, outbound requests, plugin installs, file writes, and GraphQL anomalies.

Verification steps: inventory all Spring, WordPress, Oracle, and AI inference services; confirm exact package/plugin versions; check whether WebSocket, WS-Addressing, SOAP, paginated GraphQL, and video data URL features are enabled; and validate that patches are actually deployed, not just queued.

Monitoring recommendations: alert on unexpected outbound HTTP traffic, new admin sessions, plugin changes, suspicious SOAP/XML payloads, unusual GraphQL query patterns, and spikes in memory use or service restarts.

Related Resources

  • Internal: Link to your June 11, 2026 incident response note and patch-tracking dashboard (to be published).
  • Official vendor advisories: Oracle Critical Patch Update, Spring advisories for Spring Web Services and Spring for GraphQL, WordPress plugin update notes, and the vLLM security advisory.

Keep reading