Security Digest: June 21, 2026 - 10 Critical Vulnerabilities
Today’s threat picture is urgent: multiple critical flaws allow remote code execution, privilege escalation, authentication bypass, and SQL injection across widely used apps and backend services. The highest-risk items are the SiYuan Bazaar XSS-to-RCE issues, Craft CMS admin RCE, and Capgo authorization flaws that can expose billing and identity data.
· 9 min read
Executive Summary
Today’s threat picture is urgent: multiple critical flaws allow remote code execution, privilege escalation, authentication bypass, and SQL injection across widely used apps and backend services. The highest-risk items are the SiYuan Bazaar XSS-to-RCE issues, Craft CMS admin RCE, and Capgo authorization flaws that can expose billing and identity data.
Act now: patch exposed systems immediately, disable or restrict vulnerable admin/RPC surfaces, and review logs for suspicious marketplace, SSO, RPC, and login activity.
Critical Vulnerabilities
CVE-2026-56397: SiYuan Bazaar XSS leading to remote code execution
Impact: Malicious package metadata or README content can execute JavaScript in Electron and escalate to OS command execution for any user browsing the Bazaar.
Affected Systems: SiYuan versions before v3.6.1
Immediate Action: Upgrade to v3.6.1 or later immediately. If you cannot patch, restrict Bazaar access and warn users not to browse untrusted packages.
Mitigation: Apply the vendor fix and review any third-party Bazaar content for suspicious HTML, scripts, or unexpected package metadata.
CVE-2026-56395: SiYuan Bazaar content injection enabling RCE
Impact: Attackers can inject HTML/JavaScript through package fields and trigger code execution through Electron nodeIntegration.
Affected Systems: SiYuan versions before v3.6.1
Immediate Action: Patch to v3.6.1 or later now. Treat Bazaar browsing as high risk until all clients are updated.
Mitigation: Update immediately; remove or quarantine untrusted packages and monitor endpoints for unexpected process launches.
CVE-2026-56396: phpMyFAQ authorization flaw allows SuperAdmin escalation
Impact: Authenticated admins with edit permissions can grant themselves SuperAdmin rights and take over the application.
Affected Systems: phpMyFAQ before 4.1.4
Immediate Action: Upgrade to 4.1.4 immediately. Review all admin accounts for unauthorized privilege changes.
Mitigation: Patch and audit recent changes to user roles, rights assignments, and admin activity logs.
CVE-2025-71348: picklescan misses malicious pickle payloads
Impact: Malicious pickle files can bypass detection and execute arbitrary code during deserialization, creating supply-chain risk.
Affected Systems: picklescan before 0.0.28
Immediate Action: Upgrade to 0.0.28 or later. Stop trusting pickle files from external or unverified sources.
Mitigation: Patch scanning pipelines, block untrusted pickle ingestion, and re-evaluate any artifacts accepted since the last clean scan.
CVE-2026-56239: Capgo billing function privilege escalation
Impact: Authenticated users may manipulate billing data for arbitrary organizations and deplete credits through a SECURITY DEFINER RPC.
Affected Systems: Capgo before 12.128.2
Immediate Action: Upgrade to 12.128.2 immediately and restrict RPC access until confirmed fixed.
Mitigation: Verify EXECUTE permissions on the function, audit overage events, and check for unauthorized billing changes.
CVE-2026-56242: Capgo API key oracle and identity disclosure
Impact: Attackers can confirm whether API keys are valid and map them to user IDs, then chain into organization and PII exposure.
Affected Systems: Capgo before 12.128.2
Immediate Action: Patch to 12.128.2 and rotate exposed API keys if this service is internet-accessible.
Mitigation: Disable unauthenticated access to the RPC, review API key usage, and look for enumeration patterns.
CVE-2026-12773: litellm MCP Proxy improper authentication
Impact: Remote attackers may bypass authentication in the MCP Proxy and access protected functionality.
Affected Systems: BerriAI litellm up to 1.59.8
Immediate Action: Upgrade above 1.59.8 now and restrict public exposure of the MCP Proxy.
Mitigation: Apply vendor updates, verify auth enforcement, and review proxy access logs for unauthorized sessions.
CVE-2026-12795: litellm SSO debug flow missing authentication
Impact: Attackers can reach SSO debug functionality without proper authentication, increasing the risk of account compromise and data exposure.
Affected Systems: BerriAI litellm up to 1.82.2
Immediate Action: Upgrade to a fixed release immediately and disable any debug endpoints exposed in production.
Mitigation: Patch, remove debug access from internet-facing environments, and audit SSO-related requests.
CVE-2026-12775: House-Rental-Management SQL injection in login.php
Impact: Remote attackers can inject SQL through the Username parameter, potentially leading to account compromise and database access.
Affected Systems: Montodel House-Rental-Management up to commit 90010017b81265eb1ef3810268909f7719a33863
Immediate Action: Remove public exposure of /login.php if possible and patch or replace the application immediately.
Mitigation: Apply vendor or repository fixes, validate input handling, and review database logs for injection patterns.
CVE-2026-56382: Craft CMS admin RCE via field layout preview
Impact: An authenticated admin can inject Yii2 event handlers to execute arbitrary PHP and exfiltrate secrets such as database credentials and CRAFT_SECURITY_KEY.
Affected Systems: Craft CMS 5.5.0 through 5.9.13
Immediate Action: Upgrade to 5.9.14 immediately. Restrict admin access until patched.
Mitigation: Apply the fix, rotate exposed secrets if compromise is suspected, and inspect admin actions involving field previews.
Previously Alerted
- CVE-2026-56265: CVE-2026-56265 Security Alert: CRITICAL Vulnerability
What to Do Now
- Patch internet-facing systems first, starting with SiYuan, Craft CMS, Capgo, phpMyFAQ, and litellm.
- Disable or restrict vulnerable endpoints including Bazaar browsing, RPC functions, debug flows, and admin preview features.
- Rotate credentials and API keys if any affected service was exposed externally or shows suspicious access.
- Review logs immediately for XSS payloads, unusual RPC calls, SQL injection attempts, and unexpected admin privilege changes.
- Verify versions against fixed releases before reopening access.
Verification steps:
- Confirm each product is on a fixed version.
- Check whether vulnerable functions are reachable from the network.
- Validate that admin and API permissions have not changed unexpectedly.
Monitoring recommendations:
- Alert on new SuperAdmin grants, billing anomalies, and unexpected key lookups.
- Watch for Electron child processes, shell launches, and suspicious package metadata requests.
- Monitor authentication failures, debug endpoint access, and SQL error spikes.
Related Resources
- Internal blog posts: Add links to your June 21, 2026 incident guidance and patch validation notes when published.
- Official vendor advisories: Check SiYuan, phpMyFAQ, Capgo, BerriAI litellm, Craft CMS, and the House-Rental-Management project release notes for fixed versions and mitigation guidance.