News

Vulnerability Roundup — June 2026

Louis Stowasser
Louis Stowasser
Tuesday 4 August 2026
Vulnerability Roundup — June 2026
Vulnerability Roundup — June 2026

Ivanti Sentry went from a vendor advisory on June 9 to the US government’s known-exploited list two days later. The flaw gives an unauthenticated internet attacker root-level code execution on a mobile-device-management gateway — exactly the sort of appliance that is meant to sit at a sensitive boundary. June’s defining feature was not just the volume of high-impact fixes, but how often the exposed component was either an edge service or a control plane with authority over everything behind it.

Ivanti Sentry root shell

Ivanti Sentry, formerly MobileIron Sentry, is the gateway organisations use to connect managed phones and tablets to enterprise services. CVE-2026-10520 is an operating-system command injection in releases before R10.5.2, R10.6.2 and R10.7.1. A remote attacker needs no account and can execute commands as root.

The practical exposure is narrower, but not reassuring: Ivanti says exploitation succeeds when an unmanaged Sentry appliance has externally reachable endpoints. Mutual TLS with EPMM, or restricting HTTPS access through Neurons for MDM, keeps those interfaces out of reach of outside actors. Where that is not true, this is a direct appliance takeover rather than a foothold that needs chaining.

It was added to CISA’s KEV catalogue on June 11 and a public proof of concept is available. Upgrade to the fixed release for the relevant train; access restrictions are useful containment, not a substitute for removing the vulnerable code.

PeopleSoft updates takeover

Oracle’s CVE-2026-35273 affects the Updates Environment Management component in PeopleSoft PeopleTools 8.61 and 8.62. PeopleTools underpins PeopleSoft deployments, often carrying HR, finance and other business systems that attackers would very much like to administer. The missing authentication check lets an unauthenticated attacker reaching the service over HTTP take over PeopleTools.

That alone would put it near the top of the month. Its KEV listing on June 12, plus reporting of known ransomware activity the same day, made the priority unusually clear. Oracle has issued a security alert and patches are available through its support channels. Teams should treat externally reachable PeopleSoft administration and update services as urgent exposure, not assume that the application’s business-facing login protects this component.

Windows and Apache memory bugs

Two widely deployed network foundations shipped severe memory-safety fixes. In Windows HTTP.sys, CVE-2026-47291 is an integer-overflow flaw that can allow network code execution without prior authorisation. HTTP.sys is Windows’ kernel HTTP stack, so the affected population spans listed Windows 10 and Windows 11 releases rather than a specialist server product. Microsoft has published the update; there is no exploitation or public proof-of-concept indication in this month’s material, but the pre-auth network position makes patch cadence important.

Apache HTTP Server had its own problem in CVE-2026-44631: crafted regular expressions in configuration can trigger a buffer underwrite in versions 2.4.0 through 2.4.67. That is a memory corruption issue in the web server that still fronts a substantial share of internal and public services. Apache’s answer is refreshingly direct: upgrade to 2.4.68. The advisory does not identify active exploitation, but configuration-driven failure modes deserve attention because the vulnerable setting can travel with infrastructure templates.

Jenkins and Spring deserialization

Jenkins and Spring for GraphQL are very different software, but their June flaws both put application control planes in uncomfortable territory. Jenkins controllers run builds, hold deployment credentials and often connect to source-control and production systems. With CVE-2026-53435, an attacker able to submit a controlled config.xml can cause Jenkins to deserialize arbitrary core or plugin types. They can then impersonate users, make requests as them, read controller files, and potentially reach the Script Console for arbitrary code execution. It affects Jenkins 2.567 and earlier and LTS 2.555.2 and earlier; fixed releases are available in the June advisory.

CVE-2026-41699 is an unsafe-deserialization issue in Spring for GraphQL pagination. A malicious GraphQL request can lead to remote code execution when an application exposes a paginated Connection field and its classpath contains usable deserialization gadget classes. It affects 2.0.0–2.0.3, 1.4.0–1.4.5 and 1.3.0–1.3.8, and Spring has published fixes. Neither item is flagged as exploited here, but both are a reminder that application-layer inputs can become infrastructure-level execution when a framework or CI controller processes them too generously.

Perimeters remain the pressure point

The Ivanti and PeopleSoft cases are the month’s clearest signal: unauthenticated compromise of an exposed management service became active exploitation quickly, with the latter tied to ransomware. The wider pool included another KEV-listed appliance issue, CVE-2026-20245, reinforcing that attackers are still looking for the management interfaces organisations leave reachable because they are useful.

June also had a less dramatic but consequential concentration of low-level fixes: Windows HTTP.sys and Apache joined OpenSSL (CVE-2026-45447), SQLite (CVE-2026-11822) and FreeSWITCH (CVE-2026-49841) in the memory-safety queue. Meanwhile, the ranked MariaDB issue CVE-2026-49261 can execute shell commands embedded in a joining node’s name when wsrep_notify_cmd is enabled; upgrading is best, while disabling that option is the stated workaround. SharePoint’s authorised path-traversal-to-code-execution flaw CVE-2026-45454 arrived alongside related fixes including CVE-2026-45484 and CVE-2026-47298, a useful reason to take the release as a batch rather than cherry-pick one bulletin.

The practical June priority is to find the externally reachable management, gateway and update interfaces first, then patch the Ivanti and PeopleSoft exposures before they become an incident. After that, move through the platform updates and grouped releases rather than treating each identifier in isolation; SecAlerts monitors an organisation’s actual software stack and alerts on new vulnerabilities affecting the products it runs, so teams can focus on the fixes that apply to them.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203