This week’s list is a little Windows-heavy thanks to June Patch Tuesday. Four of the five are already on CISA’s KEV list, the DHCP flaw can be triggered from the local network, and Oracle had to release an out-of-band fix for a PeopleSoft zero-day that was already being used in attacks.
1. CVE-2026-44815: Windows DHCP Client
A malicious DHCP server on the same network can send a crafted response and get code execution on Windows clients. That makes this more important than a normal workstation patch, especially on guest Wi-Fi, branch networks, or anywhere you don’t fully trust the local segment.
Scope: Windows systems using DHCP Why now: Critical, KEV-listed, CISA deadline June 23 Next step: Deploy the June 2026 Windows updates
2. CVE-2026-35273: Oracle PeopleSoft PeopleTools
Unauthenticated RCE that attackers were already using for data theft before Oracle released the fix. Any exposed or affected PeopleSoft server deserves both a patch and a closer look at what happened before it was patched.
Scope: PeopleTools 8.61 and 8.62 Why now: CVSS 9.8, KEV-listed, CISA deadline July 3 Next step: Apply Oracle’s out-of-band update and check for signs of post-exploitation activity
3. CVE-2026-0257: Palo Alto PAN-OS GlobalProtect
An authentication bypass that allows attackers to establish GlobalProtect VPN sessions without valid credentials. Since this sits at the front door of the networks running a Palo fw, log review matters almost as much as installing the fix.
Scope: Exposed GlobalProtect portals and gateways Why now: Active exploitation confirmed by Unit 42 on June 9 Next step: Apply the appropriate PAN-OS hotfix and investigate any VPN sessions you can’t explain
4. CVE-2026-10520 / CVE-2026-10523: Ivanti Sentry
This is a rough pair: one flaw allows unauthenticated root RCE, while the other can be used to create a rogue administrator account. Either one would justify urgent work on its own.
Scope: Ivanti Sentry gateway deployments Why now: CVSS 10.0 and 9.9; both KEV-listed Next step: Upgrade to the fixed release in Ivanti’s advisory
5. CVE-2026-47288: Windows Kerberos KDC
Critical RCE in the Windows Kerberos Key Distribution Center, putting domain controllers in the blast radius. There is no confirmed exploitation listed here yet, but the affected role makes delaying it a hard sell.
Scope: Windows Server domain controllers Why now: Critical, released with June 2026 Patch Tuesday Next step: Roll out the June updates, with domain controllers handled early
I try to limit these posts to 5 CVE's so it doesn't get too long, but feel free to discuss anything that missed the cut down in the comments!
libffi requests an executable stack allowing attackers to more easily trigger arbitrary code execution by overwriting the stack. Please note that libffi is used by a number of other libraries. It was previously stated that this affects libffi version 3.2.1 but this appears to be incorrect. libffi prior to version 3.1 on 32 bit x86 systems was vulnerable, and upstream is believed to have fixed this issue in version 3.1.
Unspecified vulnerability in Oracle PeopleSoft Enterprise PeopleTools 8.49 GA through 8.49.30 allows remote authenticated users to affect confidentiality via unknown vectors related to File Processing.