Weekly Security Roundup (2026-06-19-to-2026-06-26)
Your end-of-week security briefing: top CVEs and immediate priorities.
· 8 min read
Weekly Security Roundup: June 19–26, 2026
This week’s security digest was dominated by a steady stream of critical disclosures, urgent vendor alerts, and multiple high-risk application flaws across cameras, CMS platforms, backup tools, collaboration systems, and WordPress ecosystems. The most pressing issues centered on remote code execution, authentication bypass, SQL injection, XSS, SSRF, and account-takeover risks. Below is a day-by-day summary of the last seven days, followed by the top priorities security teams should address first.
Top Priorities
- Patch internet-facing systems first — especially GeoVision devices, WordPress plugins, Capgo deployments, and any exposed admin portals.
- Treat critical alerts as immediate action items — several standalone advisories this week carried CVSS scores of 9.8 or 10.
- Review for account takeover and RCE exposure — recurring themes across the week’s digests included auth bypass, privilege escalation, and remote code execution.
- Validate backups and recovery plans — backup and automation platforms such as NetVault and InsightConnect appeared in urgent fix lists.
- Prioritize web apps and plugins — WordPress, GitLab, Gogs, Budibase, and related services saw multiple high-impact issues.
June 19, 2026
- Security Digest: June 19, 2026 - 6 Critical Vulnerabilities — Six critical flaws affected pgAdmin 4, AVer cameras, and PraisonAI, with risks ranging from remote code execution to XSS and SQL injection. Severity: Critical (max CVSS 9.8).
- CVE-2026-54414 Security Alert: CRITICAL Vulnerability — Immediate action recommended for this critical issue. Severity: Critical (max CVSS 9.8).
- CVE-2026-48772 Security Alert: CRITICAL Vulnerability — A separate critical alert with maximum severity. Severity: Critical (max CVSS 10).
June 20, 2026
- Security Digest: June 20, 2026 - 6 Critical Vulnerabilities — June 20 brought urgent fixes for WordPress sites and Capgo deployments, with exposure to account takeover, file tampering, and data disclosure. Severity: Critical (max CVSS 9.8).
- CVE-2019-25763 Security Alert: CRITICAL Vulnerability — A legacy CVE resurfaced in a critical alert; immediate remediation is advised. Severity: Critical (max CVSS 9.8).
June 21, 2026
- CVE-2026-56265 Security Alert: CRITICAL Vulnerability — A standalone critical alert requiring immediate attention. Severity: Critical (max CVSS 9.8).
- Security Digest: June 21, 2026 - 10 Critical Vulnerabilities — Ten critical flaws were disclosed across SiYuan, Craft CMS, Capgo, phpMyFAQ, and litellm, including multiple RCE paths, privilege escalation bugs, and auth bypasses. Severity: Critical (max CVSS 9.6).
June 22, 2026
- Security Digest: June 22, 2026 - 2 Critical Vulnerabilities — Two high-severity XSS flaws in Pilz PASvisu and PMI systems could enable process manipulation or device takeover; patching and access restriction are strongly recommended. Severity: High (max CVSS 8.1).
- CVE-2026-10561 Security Alert: CRITICAL Vulnerability — This critical alert calls for immediate remediation. Severity: Critical (max CVSS 10).
June 23, 2026
- CVE-2026-12866 Security Alert: CRITICAL Vulnerability — Another urgent standalone advisory, rated critical. Severity: Critical (max CVSS 9.8).
- Security Digest: June 23, 2026 - 5 Critical Vulnerabilities — Five high-severity flaws in Gogs and Budibase enable XSS, org-owner takeover, SSRF, local repo import abuse, and private attachment disclosure. Severity: High (max CVSS 8.9).
- CVE-2026-54350 Security Alert: CRITICAL Vulnerability — Immediate action recommended for this maximum-severity issue. Severity: Critical (max CVSS 10).
June 24, 2026
- Security Digest: June 24, 2026 - 23 Critical Vulnerabilities — One of the busiest days of the week, with 23 critical vulnerabilities spanning GeoVision GV-I/O Box 4E remote code execution risks and numerous WordPress plugin flaws tied to account takeover, SQL injection, SSRF, and XSS. Severity: Critical (max CVSS 10).
- CVE-2026-56121 Security Alert: CRITICAL Vulnerability — A separate critical alert requiring immediate response. Severity: Critical (max CVSS 9.8).
- CVE-2026-39938 Security Alert: CRITICAL Vulnerability — Another critical advisory issued the same day. Severity: Critical (max CVSS 9.8).
June 25, 2026
- Security Digest: June 25, 2026 - 24 Critical Vulnerabilities — This broad advisory covered Quest NetVault Backup, GitLab, Rapid7 InsightConnect, Cacti, WordPress, OpenBSD, and shell-quote fixes, with urgent concerns including RCE, SQL injection, and auth bypass flaws. Severity: High (max CVSS 8.8).
- CVE-2026-56786 Security Alert: CRITICAL Vulnerability — Immediate action recommended for this critical issue. Severity: Critical (max CVSS 9.8).
June 26, 2026
- CVE-2026-57878 Security Alert: CRITICAL Vulnerability — A critical standalone alert issued at the end of the week. Severity: Critical (max CVSS 9.8).
- Security Digest: June 26, 2026 - 8 Critical Vulnerabilities — Eight critical and high-severity flaws required immediate patching, with three unauthenticated GeoVision buffer overflows standing out as the most urgent remote-code-execution risk. Severity: Critical (max CVSS 9.8).
Bottom line: The week was marked by unusually dense critical activity, especially around exposed web applications and edge devices. If your environment includes GeoVision hardware, WordPress plugins, Capgo, GitLab, Gogs, Budibase, or any of the other named products, this is a strong candidate for emergency patch review and threat hunting. Even where advisories were labeled “High,” the business impact still included takeover, data exposure, and operational disruption.