Where
-Infinity
0

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Microsoft Windows Server. Authentication is not required to exploit this vulnerability. However, only systems with Windows Deployment Services enabled are vulnerable. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-62893.

First published (updated )
Advisory
ZDI-26-544

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-50311.

First published (updated )

Hello all! Since the post last week seemed to be helpful to some folks, I figured I'd make another post this week.

The big, bad, scary one is the Netlogon RCE because it targets domain controllers and is now confirmed exploited. After that, I’d be looking at Palo Alto GlobalProtect, SolarWinds Serv-U, Cisco SD-WAN Manager, and any Linux container hosts that might still be exposed to the old cgroups v1 escape.

Here's the order I’d work them:

1. CVE-2026-41089: Microsoft Windows Netlogon

Stack-based buffer overflow in Netlogon. An unauthenticated attacker can hit a domain controller over the network and get code execution.

Affected: Windows Server 2012 R2 through 2025.

Why it matters: CVSS 9.8. Active exploitation has been confirmed by Belgium’s CCB.

Action: If your DCs got May’s cumulative update, you should be covered. If you deferred May updates on domain controllers, I’d move this to the top of the queue. Find your rollup patches here for your Server version.

2. CVE-2026-0257: Palo Alto Networks PAN-OS GlobalProtect

Authentication bypass in the GlobalProtect portal and gateway. The short version is that forged cookies can give an attacker an unauthorized VPN session.

Affected: PAN-OS firewalls with a GlobalProtect portal or gateway where authentication override cookies are enabled.

Why it matters: CVSS 9.1. Exploited in the wild and on CISA KEV.

Action: Patch to a fixed PAN-OS release. If you can’t patch immediately, disable authentication override or use a dedicated certificate only for that feature.

3. CVE-2026-28318: SolarWinds Serv-U

Unauthenticated denial of service. A crafted POST request with a Content-Encoding: deflate header can crash the Serv-U service.

Affected: Serv-U file transfer versions before 15.5.4, and 15.5.4 without Hotfix 1.

Why it matters: CVSS 7.5. Exploited in the wild. Added to CISA KEV on June 5 with a federal deadline of June 19.

Action: Update to Serv-U 15.5.4 Hotfix 1. If you need an interim move, restrict access to known IPs and block POST requests carrying a Content-Encoding header.

4. CVE-2026-20245: Cisco Catalyst SD-WAN Manager

Command injection in Cisco Catalyst SD-WAN Manager. A crafted file upload can run arbitrary commands as root.

Affected: Cisco Catalyst SD-WAN Manager, formerly vManage.

Why it matters: CVSS 7.8. Exploited as a zero-day. No patch available yet.

Action: This one does require netadmin privileges, so it is not the same kind of emergency as an unauthenticated internet-facing RCE. But with no fix available, I’d still lock down who can reach SD-WAN Manager, audit netadmin accounts, make sure MFA is solid, and watch Cisco’s advisory for the patch. You can see Cisco's additional recommendations here.

5. CVE-2022-0492: Linux kernel cgroups v1 container escape

Old bug, but newly relevant again because CISA added it to KEV last week. The cgroups v1 releaseagent issue can let a low-privileged local user escape a container and escalate to root.

Affected: Linux hosts running containers on unpatched kernels or with overly permissive container configs.

Why it matters: CVSS 7.8. Added to CISA KEV on June 2 based on evidence of active exploitation.

Action: Check your container hosts. Make sure kernels are patched, containers are not running with CAPSYSADMIN, and AppArmor/SELinux/Seccomp profiles are actually enforced.

Three of these are on CISA KEV: Palo Alto, Serv-U, and the Linux cgroups bug.

If I only had time to clear one, I’d start with Netlogon. Unauthenticated RCE against domain controllers is not something I’d want sitting around, especially now that exploitation has been confirmed.

Serv-U would be next if it is internet-facing, then Palo Alto GlobalProtect if authentication override is enabled.

Also worth noting: Check Point Remote Access VPN CVE-2026-50751 and LiteLLM CVE-2026-42271 both landed on KEV after this window, so they’ll probably be in next week’s batch.

If you like the format, please consider checking out my newsletter! Link is on my profile page.

First published (updated )
Social
reddit
Severity
7.5
Infoleak
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C

Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

1 / 2
Source: Microsoft
First published (updated )

So from what I could find there is not much information on this vulnerability. Based on CVE-2026-27913 - Security Update Guide - Microsoft - Windows BitLocker Security Feature Bypass Vulnerability only Windows servers are patched now however I would guess this affects user-end machines as well if not more. Are there any official sources saying if this is patched for users too? And if so which update did that. Thanks

First published (updated )
Social
reddit

So we have DCs that are fully patched with all Windows Updates until this months.

Kerberos success and failure auditing is enabled in audit policy.

We are not seeing a SINGLE event ID 201-209 in the System event logs.

I thought from this article that meant we are good.

https://support.microsoft.com/en-us/topic/how-to-manage-kerberos-kdc-usage-of-rc4-for-service-account-ticket-issuance-changes-related-to-cve-2026-20833-1ebcda33-720a-4da8-93c1-b0496e1910dc

However it looks from running the ".\\Get-KerbEncryptionUsage.ps1 -Encryption RC4" script we are still using RC4 on a handful of computer or service accounts.

Ticket : RC4

SessionKey : AES256-SHA96

I believe I can use the "RC4DefaultDisablementPhase" reg key to buy us a few months whilst I understand this - but there seems to be a bunch of contradicting articles.

Which do I trust please?

First published (updated )
Social
reddit
Severity
8.2
AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

An arbitrary write vulnerability in Microsoft signed UEFI firmware allows for code execution of untrusted software. This allows an attacker to control its value, leading to arbitrary memory writes, including modification of critical firmware settings stored in NVRAM. Exploiting this vulnerability could enable security bypasses, persistence mechanisms, or full system compromise.

1 / 3
Source: NVD
First published (updated )
Severity
7.8
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

UNSUPPORTED WHEN ASSIGNED

A privilege escalation vulnerability in CxUIUSvc64.exe and CxUIUSvc32.exe of Synaptics audio drivers allows a local authorized attacker to load a DLL in a privileged process.

Out of an abundance of caution, this CVE ID is being assigned to better serve our customers and ensure all who are still running this product understand that the product is End-of-Life and should be removed. For more information on this, refer to the CVE Record’s reference information.

1 / 2
Source: MITRE
First published (updated )
Severity
8.2
AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Cert CC: CVE-2024-7344 Howyar Taiwan Secure Boot Bypass

1 / 3
Source: Microsoft
First published (updated )
Severity
7.8
Integer Overflow
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Windows Registry Elevation of Privilege Vulnerability

First published (updated )
Severity
7.8
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Win32k Elevation of Privilege Vulnerability

First published (updated )
Severity
8.8
Integer Overflow
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Windows Telephony Service Remote Code Execution Vulnerability

First published (updated )
Severity
9.8
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Windows KDC Proxy Remote Code Execution Vulnerability

First published (updated )
Severity
7.8
EPSS
22.94%
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Active Directory Certificate Services Elevation of Privilege Vulnerability

First published (updated )
Severity
6.8
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Windows USB Video Class System Driver Elevation of Privilege Vulnerability

First published (updated )
Severity
8.8
Integer Overflow
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Windows Telephony Service Remote Code Execution Vulnerability

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203