<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>PatchNow - High Risk Vulnerability Alerts</title>
    <link>https://patchnow.workshop1.net</link>
    <description>Critical vulnerability alerts for T1190 (Exploit Public-Facing Application) risks from CISA KEV catalog with internet-facing deployment analysis</description>
    <language>en-us</language>
    <lastBuildDate>Thu, 04 Jun 2026 09:50:37 -0000</lastBuildDate>
    <generator>PatchNow Intelligence System</generator>
    <webMaster>security@workshop1.net</webMaster>
    <managingEditor>security@workshop1.net</managingEditor>
    <ttl>60</ttl>
    <atom:link href="https://patchnow.workshop1.net/rss.xml" rel="self" type="application/rss+xml" />
    <category>Security</category>
    <item>
      <title>CVE-2026-45247</title>
      <link>https://patchnow.workshop1.net/cve/cve-2026-45247.html</link>
      <guid>https://patchnow.workshop1.net/cve/cve-2026-45247.html</guid>
      <description>&lt;p&gt;Critical PHP object injection vulnerability in Mirasvit Cache Warmer for Magento 2 allows unauthenticated remote code execution via crafted cookie data. Affects e-commerce platforms that are inherently internet-facing by design. CISA KEV listing confirms active exploitation.&lt;/p&gt;
&lt;h4&gt;Risk Assessment&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CVSS Score:&lt;/strong&gt; 9.8&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MITRE ATT&amp;CK:&lt;/strong&gt; T1190&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Internet Exposure:&lt;/strong&gt; VERY_HIGH&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Affected Products&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Magento 2 with Mirasvit Cache Warmer&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Key Recommendations&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;CRITICAL: Check for indicators of compromise - this vulnerability is in CISA KEV indicating active exploitation in the wild. Review logs, check for unauthorized access, verify system integrity&lt;/li&gt;
&lt;li&gt;Immediately update Mirasvit Full Page Cache Warmer to version 1.11.12 or later&lt;/li&gt;
&lt;li&gt;Review web server access logs for suspicious cookie values or serialized PHP objects in CacheWarmer cookies&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;a href="https://patchnow.workshop1.net/cve/cve-2026-45247.html"&gt;View full analysis →&lt;/a&gt;&lt;/p&gt;</description>
      <category>High Risk</category>
      <category>MITRE-T1190</category>
      <pubDate>Thu, 04 Jun 2026 06:53:20 -0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-0257</title>
      <link>https://patchnow.workshop1.net/cve/cve-2026-0257.html</link>
      <guid>https://patchnow.workshop1.net/cve/cve-2026-0257.html</guid>
      <description>&lt;p&gt;Authentication bypass vulnerability in GlobalProtect portal/gateway components of Palo Alto Networks PAN-OS allows remote attackers to establish unauthorized VPN connections. Active exploitation confirmed with public PoC available.&lt;/p&gt;
&lt;h4&gt;Risk Assessment&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CVSS Score:&lt;/strong&gt; 7.8&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MITRE ATT&amp;CK:&lt;/strong&gt; T1190&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Internet Exposure:&lt;/strong&gt; VERY_HIGH&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Affected Products&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;PAN-OS&lt;/li&gt;
&lt;li&gt;Prisma Access&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Key Recommendations&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;CRITICAL: Check for indicators of compromise - this vulnerability is in CISA KEV indicating active exploitation in the wild. Review VPN logs for unauthorized connections, check for suspicious authentication patterns, verify user session legitimacy&lt;/li&gt;
&lt;li&gt;Immediately apply vendor patches per upgrade matrix or implement workarounds (disable authentication override cookies or use dedicated certificates)&lt;/li&gt;
&lt;li&gt;Monitor GlobalProtect logs for unusual connection patterns, failed authentication attempts, or connections from unexpected geographic locations&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;a href="https://patchnow.workshop1.net/cve/cve-2026-0257.html"&gt;View full analysis →&lt;/a&gt;&lt;/p&gt;</description>
      <category>High Risk</category>
      <category>MITRE-T1190</category>
      <pubDate>Sat, 30 May 2026 19:25:26 -0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-48172</title>
      <link>https://patchnow.workshop1.net/cve/cve-2026-48172.html</link>
      <guid>https://patchnow.workshop1.net/cve/cve-2026-48172.html</guid>
      <description>&lt;p&gt;Critical privilege escalation vulnerability in LiteSpeed cPanel/WHM plugins allowing attackers to potentially gain root access via network exploitation. This vulnerability is actively exploited in the wild and affects widely deployed web hosting control panel systems.&lt;/p&gt;
&lt;h4&gt;Risk Assessment&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CVSS Score:&lt;/strong&gt; 10.0&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MITRE ATT&amp;CK:&lt;/strong&gt; T1190&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Internet Exposure:&lt;/strong&gt; VERY_HIGH&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Affected Products&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;LiteSpeed cPanel Plugin (versions 2.3 to &lt; 2.4.7)&lt;/li&gt;
&lt;li&gt;LiteSpeed WHM Plugin (versions &lt; 5.3.1.0)&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Key Recommendations&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;CRITICAL: Check for indicators of compromise - this vulnerability is in CISA KEV indicating active exploitation in the wild. Run detection command: grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2&gt;/dev/null&lt;/li&gt;
&lt;li&gt;IMMEDIATE: Update LiteSpeed WHM Plugin to version 5.3.1.0 and cPanel Plugin to version 2.4.7&lt;/li&gt;
&lt;li&gt;URGENT: Examine system logs for suspicious IP addresses and block any unauthorized access attempts&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;a href="https://patchnow.workshop1.net/cve/cve-2026-48172.html"&gt;View full analysis →&lt;/a&gt;&lt;/p&gt;</description>
      <category>High Risk</category>
      <category>MITRE-T1190</category>
      <pubDate>Wed, 27 May 2026 18:00:41 -0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-9082</title>
      <link>https://patchnow.workshop1.net/cve/cve-2026-9082.html</link>
      <guid>https://patchnow.workshop1.net/cve/cve-2026-9082.html</guid>
      <description>&lt;p&gt;Critical unauthenticated SQL injection vulnerability in Drupal core affecting installations using PostgreSQL databases. Allows direct remote exploitation of internet-facing Drupal websites for full database access and potential remote code execution.&lt;/p&gt;
&lt;h4&gt;Risk Assessment&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CVSS Score:&lt;/strong&gt; 9.1&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MITRE ATT&amp;CK:&lt;/strong&gt; T1190&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Internet Exposure:&lt;/strong&gt; VERY_HIGH&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Affected Products&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Drupal 8.9.0 through 10.4.9&lt;/li&gt;
&lt;li&gt;Drupal 10.5.0 through 10.5.9&lt;/li&gt;
&lt;li&gt;Drupal 10.6.0 through 10.6.8&lt;/li&gt;
&lt;li&gt;Drupal 11.0.0 through 11.1.9&lt;/li&gt;
&lt;li&gt;Drupal 11.2.0 through 11.2.11&lt;/li&gt;
&lt;li&gt;&lt;em&gt;...and 1 more&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Key Recommendations&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;URGENT: Immediately update all Drupal installations to patched versions (10.4.10+, 10.5.10+, 10.6.9+, 11.1.10+, 11.2.12+, 11.3.10+)&lt;/li&gt;
&lt;li&gt;Prioritize Drupal sites using PostgreSQL databases as they are specifically vulnerable&lt;/li&gt;
&lt;li&gt;Review web server logs for suspicious SQL injection attempts or unusual database queries&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;a href="https://patchnow.workshop1.net/cve/cve-2026-9082.html"&gt;View full analysis →&lt;/a&gt;&lt;/p&gt;</description>
      <category>High Risk</category>
      <category>MITRE-T1190</category>
      <pubDate>Fri, 22 May 2026 18:25:36 -0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-42897</title>
      <link>https://patchnow.workshop1.net/cve/cve-2026-42897.html</link>
      <guid>https://patchnow.workshop1.net/cve/cve-2026-42897.html</guid>
      <description>&lt;p&gt;CVE-2026-42897 is a cross-site scripting vulnerability in Microsoft Exchange Server that enables spoofing attacks. This vulnerability is actively exploited in the wild and affects widely deployed internet-facing email servers through crafted network requests.&lt;/p&gt;
&lt;h4&gt;Risk Assessment&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CVSS Score:&lt;/strong&gt; 8.1&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MITRE ATT&amp;CK:&lt;/strong&gt; T1190&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Internet Exposure:&lt;/strong&gt; VERY_HIGH&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Affected Products&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Exchange Server 2019&lt;/li&gt;
&lt;li&gt;Exchange Server 2016&lt;/li&gt;
&lt;li&gt;Exchange Server Subscription Edition&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Key Recommendations&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;CRITICAL: Check for indicators of compromise - this vulnerability is in CISA KEV indicating active exploitation in the wild. Review Exchange server logs, check for unauthorized access, verify system integrity, and examine web access logs for suspicious crafted requests&lt;/li&gt;
&lt;li&gt;Apply Microsoft security updates immediately for all affected Exchange Server versions (2016 CU23, 2019 CU14/CU15, Subscription Edition RTM)&lt;/li&gt;
&lt;li&gt;Monitor Exchange server web traffic for malicious requests and implement web application firewall rules to detect XSS attempts&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;a href="https://patchnow.workshop1.net/cve/cve-2026-42897.html"&gt;View full analysis →&lt;/a&gt;&lt;/p&gt;</description>
      <category>High Risk</category>
      <category>MITRE-T1190</category>
      <pubDate>Fri, 15 May 2026 17:30:43 -0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-20182</title>
      <link>https://patchnow.workshop1.net/cve/cve-2026-20182.html</link>
      <guid>https://patchnow.workshop1.net/cve/cve-2026-20182.html</guid>
      <description>&lt;p&gt;Critical authentication bypass in Cisco Catalyst SD-WAN Manager allows unauthenticated remote attackers to gain administrative privileges through crafted requests. This vulnerability is actively being exploited in the wild and is listed in CISA's KEV catalog.&lt;/p&gt;
&lt;h4&gt;Risk Assessment&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CVSS Score:&lt;/strong&gt; 10.0&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MITRE ATT&amp;CK:&lt;/strong&gt; T1190&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Internet Exposure:&lt;/strong&gt; HIGH&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Affected Products&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Cisco Catalyst SD-WAN Manager&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Key Recommendations&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;CRITICAL: Check for indicators of compromise - this vulnerability is in CISA KEV indicating active exploitation in the wild. Review logs, check for unauthorized access, verify system integrity&lt;/li&gt;
&lt;li&gt;Immediately upgrade to fixed software releases as recommended by Cisco advisory cisco-sa-sdwan-rpa2-v69WY2SW&lt;/li&gt;
&lt;li&gt;Implement network segmentation to restrict access to SD-WAN Manager interfaces&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;a href="https://patchnow.workshop1.net/cve/cve-2026-20182.html"&gt;View full analysis →&lt;/a&gt;&lt;/p&gt;</description>
      <category>High Risk</category>
      <category>MITRE-T1190</category>
      <pubDate>Thu, 14 May 2026 17:45:33 -0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-42208</title>
      <link>https://patchnow.workshop1.net/cve/cve-2026-42208.html</link>
      <guid>https://patchnow.workshop1.net/cve/cve-2026-42208.html</guid>
      <description>&lt;p&gt;Critical SQL injection vulnerability in LiteLLM proxy server allowing unauthenticated attackers to read/modify database contents including API keys and credentials. Actively exploited within 36 hours of disclosure and added to CISA KEV catalog.&lt;/p&gt;
&lt;h4&gt;Risk Assessment&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CVSS Score:&lt;/strong&gt; 9.3&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MITRE ATT&amp;CK:&lt;/strong&gt; T1190&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Internet Exposure:&lt;/strong&gt; HIGH&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Affected Products&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;LiteLLM Proxy Server (versions 1.81.16 to 1.83.6)&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Key Recommendations&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;CRITICAL: Check for indicators of compromise - this vulnerability is in CISA KEV indicating active exploitation in the wild. Review logs, check for unauthorized access, verify system integrity&lt;/li&gt;
&lt;li&gt;Immediately upgrade to LiteLLM version 1.83.7 or later&lt;/li&gt;
&lt;li&gt;Review database logs for suspicious SQL queries or unauthorized data access&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;a href="https://patchnow.workshop1.net/cve/cve-2026-42208.html"&gt;View full analysis →&lt;/a&gt;&lt;/p&gt;</description>
      <category>High Risk</category>
      <category>MITRE-T1190</category>
      <pubDate>Sat, 09 May 2026 17:45:55 -0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-0300</title>
      <link>https://patchnow.workshop1.net/cve/cve-2026-0300.html</link>
      <guid>https://patchnow.workshop1.net/cve/cve-2026-0300.html</guid>
      <description>&lt;p&gt;Critical unauthenticated buffer overflow vulnerability in Palo Alto PAN-OS User-ID Authentication Portal allowing remote code execution with root privileges. Already under active exploitation in the wild against internet-facing firewalls.&lt;/p&gt;
&lt;h4&gt;Risk Assessment&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CVSS Score:&lt;/strong&gt; 9.3&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MITRE ATT&amp;CK:&lt;/strong&gt; T1190&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Internet Exposure:&lt;/strong&gt; HIGH&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Affected Products&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Palo Alto PAN-OS (PA-Series firewalls)&lt;/li&gt;
&lt;li&gt;Palo Alto PAN-OS (VM-Series firewalls)&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Key Recommendations&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;CRITICAL: Check for indicators of compromise - this vulnerability is in CISA KEV indicating active exploitation in the wild. Review logs, check for unauthorized access, verify system integrity&lt;/li&gt;
&lt;li&gt;IMMEDIATE: Apply security patches listed in the advisory (PAN-OS versions 12.1.7, 11.2.12, 11.1.15, 10.2.18-h6 and their respective hotfixes)&lt;/li&gt;
&lt;li&gt;URGENT: If patching cannot be completed immediately, restrict User-ID Authentication Portal access to only trusted internal IP addresses and disable Response Pages on internet-facing interfaces&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;a href="https://patchnow.workshop1.net/cve/cve-2026-0300.html"&gt;View full analysis →&lt;/a&gt;&lt;/p&gt;</description>
      <category>High Risk</category>
      <category>MITRE-T1190</category>
      <pubDate>Thu, 07 May 2026 19:20:47 -0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-6973</title>
      <link>https://patchnow.workshop1.net/cve/cve-2026-6973.html</link>
      <guid>https://patchnow.workshop1.net/cve/cve-2026-6973.html</guid>
      <description>&lt;p&gt;CVE-2026-6973 is an OS command injection vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that allows authenticated administrators to achieve remote code execution. EPMM is typically deployed as an internet-facing mobile device management server, making this a direct network exploitation risk.&lt;/p&gt;
&lt;h4&gt;Risk Assessment&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CVSS Score:&lt;/strong&gt; 7.2&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MITRE ATT&amp;CK:&lt;/strong&gt; T1190&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Internet Exposure:&lt;/strong&gt; HIGH&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Affected Products&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Ivanti Endpoint Manager Mobile (EPMM)&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Key Recommendations&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;IMMEDIATE: Update to patched versions 12.6.1.1, 12.7.0.1, or 12.8.0.1 depending on your current branch&lt;/li&gt;
&lt;li&gt;Audit administrative accounts with access to EPMM console for unauthorized access or suspicious activity&lt;/li&gt;
&lt;li&gt;Review EPMM server logs for evidence of command injection attempts or unusual administrative activity&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;a href="https://patchnow.workshop1.net/cve/cve-2026-6973.html"&gt;View full analysis →&lt;/a&gt;&lt;/p&gt;</description>
      <category>High Risk</category>
      <category>MITRE-T1190</category>
      <pubDate>Thu, 07 May 2026 16:25:37 -0000</pubDate>
    </item>
  </channel>
</rss>