ZDI-26-388: Oracle PeopleSoft HubMBeanPersistance Deserialization of Untrusted Data Remote Code Execution Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle PeopleSoft. Although authentication is required to... 25/06/2026 Zero-Day Initiative
ZDI-26-387: Oracle PeopleSoft HttpListeningConnector Server-Side Request Forgery Vulnerability This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Oracle PeopleSoft. Authentication is not required... 25/06/2026 Zero-Day Initiative
ZDI-26-386: Unraid Web Server ToggleState Command Injection Remote Code Execution Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of Unraid. Authentication is required to exploit this... 25/06/2026 Zero-Day Initiative
ZDI-26-385: Unraid Web Server FileUpload Command Injection Remote Code Execution Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of Unraid. Authentication is required to exploit this... 25/06/2026 Zero-Day Initiative
ZDI-26-384: MosaicML Composer Deserialization of Untrusted Data Remote Code Execution Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of MosaicML Composer. User interaction is required to... 25/06/2026 Zero-Day Initiative
ZDI-26-383: ATEN Unizon doCryptoHugeFileToFile Improper Verification of Cryptographic Signature Remote Code Execution Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of ATEN Unizon. Authentication is required to exploit... 25/06/2026 Zero-Day Initiative
CVE‑2026‑35273 — Defending Against the Oracle PeopleSoft PSEMHUB Authentication Bypass Summary CVE–2026–35273 is an actively exploited, unauthenticated remote code execution vulnerability in Oracle PeopleSoft Enterprise PeopleTools — not a routine critical–CVE patch. Oracle disclosed it on... 19/06/2026 Qualys-Threat-Protect
Oracle Critical Patch Update, June 2026 Security Update Review Oracle released its third quarterly edition of this year’s Critical Patch Update. The update received patches for 245 security vulnerabilities. Some of the... 19/06/2026 Qualys-Threat-Protect
Microsoft Defender Zero-day Vulnerability Exploited in Attacks (CVE-2026-50656) (RoguePlanet) Microsoft announced the active exploitation of a Defender zero-day named RoguePlanet. Tracked as CVE-2026-50656, successful exploitation of the vulnerability may allow an attacker to gain SYSTEM-level access. Microsoft... 19/06/2026 Qualys-Threat-Protect
Cisco Identity Services Engine RCE and Information Disclosure Vulnerabilities (CVE-2026-20181 & CVE-2026-20190) Cisco released security updates to address two vulnerabilities impacting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). Tracked as CVE-2026-20181... 19/06/2026 Qualys-Threat-Protect