Weekly Security Roundup (2026-06-12-to-2026-06-19)
Your end-of-week security briefing: top CVEs and immediate priorities.
· 9 min read
Weekly Security Roundup: June 12–19, 2026
Over the past seven days, security teams faced a relentless stream of critical and high-severity disclosures spanning web applications, WordPress ecosystems, network appliances, remote management tools, and developer platforms. This week’s alerts were dominated by urgent patching guidance, public exploit activity, and vulnerabilities that could lead to remote code execution, takeover, SQL injection, and privilege escalation. Below is a day-by-day summary of the most important digests and alerts, followed by the top priorities for defenders.
Top Priorities
- Patch internet-facing systems first — especially WordPress, shared hosting, remote management, and developer collaboration platforms.
- Investigate exposed devices and services — several advisories mention public exploits or active abuse risk.
- Restrict access and isolate vulnerable assets until patches are applied, particularly for routers, cameras, and admin consoles.
- Review for signs of compromise where vulnerabilities could enable unauthenticated command execution, takeover, or token bypass.
- Prioritize critical alerts with CVSS 9.8–9.9, as these represent the highest immediate operational risk.
June 12, 2026
-
Security Digest: June 12, 2026 - 11 Critical Vulnerabilities
Severity: CRITICAL (max CVSS 9.9)
This major digest opens the week with urgent patches for UniFi OS, WordPress Toolkit, IEI Remote Management, OAuth-related issues, and other high-risk flaws. The affected CVEs include CVE-2026-47369, CVE-2026-47365, CVE-2026-47370, CVE-2026-47367, CVE-2026-11849, CVE-2026-48611, CVE-2026-11933, CVE-2026-12059, CVE-2026-48612, CVE-2026-44892, and CVE-2026-47366. -
CVE-2026-10557 Security Alert: CRITICAL Vulnerability
Severity: CRITICAL (max CVSS 9.8)
A standalone critical alert calling for immediate action. As with similar alerts this week, defenders should patch quickly and verify exposure on affected systems.
June 13, 2026
-
CVE-2026-12183 Security Alert: CRITICAL Vulnerability
Severity: CRITICAL (max CVSS 9.8)
Another urgent critical advisory requiring immediate remediation. -
Security Digest: June 13, 2026 - 4 Critical Vulnerabilities
Severity: HIGH (max CVSS 7.6)
This digest highlights two SQL injection flaws and two WordPress XSS issues that warrant immediate patching and exposure checks. The CVEs listed are CVE-2026-6428, CVE-2026-9848, CVE-2026-9109, and CVE-2026-5513.
June 14, 2026
-
Security Digest: June 14, 2026 - 2 Critical Vulnerabilities
Severity: HIGH (max CVSS 8.5)
Two high-severity flaws demand immediate attention: an exploited LiteSpeed shared-hosting issue and a remote iso14229 UDS crash/memory-read bug. The CVEs are CVE-2026-54420 and CVE-2026-54413.
June 15, 2026
-
Security Digest: June 15, 2026 - 10 Critical Vulnerabilities
Severity: HIGH (max CVSS 8.8)
This digest focuses on ten high-severity flaws, including public exploits in Yealink devices and Ruijie routers. The recommended response is immediate patching, isolation, and access restriction. CVEs include CVE-2026-12192, CVE-2026-12218, CVE-2026-12220, CVE-2026-12221, CVE-2026-12222, CVE-2026-50100, CVE-2026-12198, CVE-2026-12204, CVE-2026-12200, and CVE-2026-12197. -
CVE-2018-25436 Security Alert: CRITICAL Vulnerability
Severity: CRITICAL (max CVSS 9.8)
A legacy critical alert that underscores the importance of checking older, potentially forgotten software and appliances still in production.
June 16, 2026
-
CVE-2026-49774 Security Alert: CRITICAL Vulnerability
Severity: CRITICAL (max CVSS 9.9)
A top-tier critical alert with immediate remediation recommended. -
Security Digest: June 16, 2026 - 15 Critical Vulnerabilities
Severity: CRITICAL (max CVSS 9.9)
One of the largest digests of the week, this release covers 15 critical WordPress and web app vulnerabilities. Issues include unauthenticated SQL injection, file upload flaws, remote code execution, and privilege escalation. CVEs listed are CVE-2026-40750, CVE-2026-52715, CVE-2026-49772, CVE-2026-39574, CVE-2026-8444, CVE-2026-6933, CVE-2026-8443, CVE-2026-39581, CVE-2026-8442, CVE-2026-52712, CVE-2026-52711, CVE-2026-8176, CVE-2026-39437, CVE-2026-54191, and CVE-2026-54198. -
CVE-2026-54310 Security Alert: MEDIUM Vulnerability
Severity: CRITICAL (max CVSS 9.9)
The severity label appears inconsistent with the alert text, but the message still advises immediate action. Treat this as a high-priority item until verified.
June 17, 2026
-
Security Digest: June 17, 2026 - 5 Critical Vulnerabilities
Severity: CRITICAL (max CVSS 9.8)
Five urgent flaws affect rclone, Gitea, and Gogs, including unauthenticated command execution, repository takeover, and token-scope bypasses. The CVEs are CVE-2026-49980, CVE-2026-26231, CVE-2026-52797, CVE-2026-28699, and CVE-2026-28744. -
CVE-2025-60229 Security Alert: CRITICAL Vulnerability
Severity: CRITICAL (max CVSS 9.8)
Another critical alert urging immediate remediation, including validation of whether the vulnerable component is exposed or still in use.
June 18, 2026
-
CVE-2026-55740 Security Alert: CRITICAL Vulnerability
Severity: CRITICAL (max CVSS 9.8)
A critical standalone advisory with immediate action recommended. -
Security Digest: June 18, 2026 - 10 Critical Vulnerabilities
Severity: CRITICAL (max CVSS 9.6)
This digest spans Cotonti, TypeBot, WordPress plugins, and cifs-utils. The vulnerabilities include urgent issues that may enable exploitation now, so patching should be prioritized immediately. CVEs listed are CVE-2026-55742, CVE-2026-48768, CVE-2026-12407, CVE-2026-9860, CVE-2026-55741, CVE-2026-48764, CVE-2026-55744, CVE-2026-12505, CVE-2026-55746, and CVE-2026-11395. -
CVE-2026-38715 Security Alert: CRITICAL Vulnerability
Severity: CRITICAL (max CVSS 9.8)
Yet another critical alert in a week packed with high-risk disclosures.
June 19, 2026
-
Security Digest: June 19, 2026 - 6 Critical Vulnerabilities
Severity: CRITICAL (max CVSS 9.8)
The week closes with six critical flaws affecting pgAdmin 4, AVer cameras, and PraisonAI. Risks include remote code execution, XSS, and SQL injection. CVEs listed are CVE-2026-40624, CVE-2026-12048, CVE-2026-12045, CVE-2026-12046, CVE-2026-12044, and CVE-2026-56076. -
CVE-2026-54414 Security Alert: CRITICAL Vulnerability
Severity: CRITICAL (max CVSS 9.8)
Final-day critical alert: immediate action recommended.
Bottom line: This week was dominated by critical web-facing and infrastructure vulnerabilities, with repeated emphasis on immediate patching, exposure review, and isolation of vulnerable systems. Organizations should focus first on externally reachable services, products with public exploit reports, and any systems that handle authentication, file uploads, or administrative access.