June 21, 2026
- CVE-2026-20253, a critical unauthenticated arbitrary-file-write in the Splunk Enterprise PostgreSQL sidecar, is under active exploitation days after disclosure — CISA gave federal agencies a three-day patch deadline. The same advisory cluster includes an RCE via unsafe deserialization (CVE-2026-20251) (BleepingComputer, Horizon3).
· Vulnerabilities & Exploits
in FortiBleed Exposes 86,000 FortiGate Devices as North Korea's Sapphire Sleet Poisons the Mastra npm Catalog
June 20, 2026
- Splunk Enterprise CVE-2026-20253, an unauthenticated arbitrary file write in the PostgreSQL sidecar enabling RCE, is being exploited days after disclosure; CISA gave agencies a three-day patch window. Fixed in 10.0.7+/10.2.4+. BleepingComputer, Horizon3
· Vulnerabilities & Exploits
in FortiBleed Burns 86,000 FortiGate Devices as Novo Nordisk Loses 1.3TB — Including AI Models — to a Leaked GitHub Token
June 19, 2026
- Splunk Enterprise CVE-2026-20253, an unauthenticated arbitrary file write in the PostgreSQL sidecar that can chain to RCE, is being exploited days after disclosure; CISA gave agencies a three-day patch window (SecurityWeek, Horizon3).
· Vulnerabilities & Exploits
in FortiBleed Burns 70,000+ Fortinet Edge Devices While a Leaked GitHub Token Guts Novo Nordisk
June 18, 2026
- Splunk Enterprise CVE-2026-20253 (CVSS 9.8) is a pre-auth RCE: an arbitrary file write in the bundled PostgreSQL sidecar that watchTowr turned into code execution by abusing database-level auth. Fixed in 10.0.7+ / 10.2.4+ (watchTowr Labs, Horizon3).
· Vulnerabilities & Exploits
in ShinyHunters Burns a PeopleSoft Zero-Day Through Higher Ed as Copilot "SearchLeak" Shows AI Is the New Exfil Channel