VYPR
AI Brief2026-06-14· generated Jun 14, 2026

ShinyHunters Oracle Zero-Day Added to KEV

CISA flags an Oracle PeopleSoft zero-day exploited by ShinyHunters as Microsoft patches 200 flaws and Aqara discloses seven critical cloud vulnerabilities.

CISA adds an Oracle PeopleSoft zero-day exploited by the ShinyHunters ransomware group to the Known Exploited Vulnerabilities catalog, as the group claims over 100 organizations — primarily universities — have been breached. CVE-2026-35273 is a critical, unauthenticated remote code execution vulnerability in PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62, with a CVSS of 9.8 and an EPSS score of 0.22 (∼22% probability of exploitation in the wild). Mandiant reported that ShinyHunters has been actively exploiting the flaw since at least late May 2026, targeting the education sector for data theft and extortion. The Register and Dark Reading both covered the group's claims of compromising over 100 institutions. Oracle released an out-of-band security alert and mitigation guidance, though a full patch may not be available until the July 2026 Critical Patch Update. CISA's KEV listing mandates federal agencies remediate by July 2, 2026.

Microsoft's June 2026 Patch Tuesday addresses 198 vulnerabilities, including six zero-days, with a critical tampering flaw in Windows DHCP Server (CVE-2026-45602) standing out among the batch. CVE-2026-45602 carries a CVSS of 9.1 and allows an unauthenticated attacker to perform tampering over the network against Windows DHCP Server, a core infrastructure component in enterprise environments. BleepingComputer reported that three of the six zero-days were publicly known at the time of release, though none were listed as actively exploited. The sheer volume — 200+ flaws — makes prioritization difficult, but the DHCP Server vulnerability should be treated as emergency-band given its critical severity and network-level attack vector.

Aqara disclosed a cascade of seven critical vulnerabilities across its cloud platform, IAM/SSO gateway, and Android mobile SDK, collectively exposing smart-home infrastructure to account takeover, data theft, and unauthorized device control. CVE-2026-50086 (CVSS 10.0) exposes bidirectional AES round-trips against the platform's signing key without authentication, while CVE-2026-50084 (CVSS 9.6) allows any valid developer token to access any account. CVE-2026-50090 (CVSS 9.3) is an OAuth redirect bypass, and CVE-2026-50083 (CVSS 9.1) stems from hardcoded OAuth client credentials in the IAM/SSO gateway. On the mobile side, CVE-2026-50091 (CVSS 9.1) involves hardcoded cryptographic keys in the Aqara Home Android app and white-label clients. Together, these flaws mean an attacker who compromises any single piece of the Aqara ecosystem — a developer token, a mobile app, or network access to the gateway — can pivot to full account and device compromise across the platform.

Google Chrome 149 patches 25 security bugs, including over a dozen sandbox escape vulnerabilities, with CVE-2026-12027 (CVSS 9.6) representing the most critical of the batch. CVE-2026-12027 is an inappropriate implementation in Headless Chrome that allows a remote attacker who has already compromised the renderer process to escape the sandbox via a crafted HTML page. As Vypr Intelligence reported, the sheer number of sandbox escapes in this release is unusual and suggests a systemic weakness in Chrome's sandbox architecture. Enterprise security teams should prioritize this update given that sandbox escape chains are frequently used in commercial spyware and advanced persistent threat operations.

Two open-source projects — vm2 and ApostropheCMS — received large coordinated vulnerability disclosures, with vm2 disclosing nine sandbox escape CVEs and ApostropheCMS disclosing nine CVEs including two critical flaws. In vm2, CVE-2026-47140 and CVE-2026-47131 (both CVSS 10.0) bypass the Node.js sandbox's denylist of dangerous builtins, allowing arbitrary code execution on the host. Vypr Intelligence noted that the vm2 project has been deprecated in favor of Node.js' built-in node:vm module, meaning users must migrate rather than patch. In ApostropheCMS, CVE-2026-53609 (CVSS 9.1) allows an authenticated editor to achieve prototype pollution via apos.util.set(), while CVE-2026-53608 (CVSS 8.7) is a server-side template injection through the SEO module's Google Analytics and Tag Manager ID fields. Vypr Intelligence covered the full batch.

Naxclow IoT devices and Nezha Monitoring both disclosed critical vulnerabilities that enable device takeover and lateral movement in operational technology and monitoring environments. CVE-2026-28742 (CVSS 9.8) affects Naxclow devices through a hardcoded, platform-wide signing salt embedded in firmware, allowing attackers to forge valid signatures for any device or API request. CVE-2026-42947 (CVSS 8.8) is a device reassignment flaw in the same platform's onboarding workflow. CISA's ICS advisory covers both. In Nezha Monitoring, CVE-2026-46716 (CVSS 9.9) allows a RoleMember user to create scheduled cron tasks with arbitrary command execution, effectively granting privilege escalation. Vypr Intelligence reported that 13 CVEs were disclosed for Nezha in total, with this being the most severe.

Additional critical vulnerabilities were disclosed in SimpleHelp remote support software, QNAP QTS, OpenClaw, ChromaDB, and the AWS Common Runtime library, each requiring urgent attention from affected users. CVE-2026-48558 (CVSS 10.0) is an authentication bypass in SimpleHelp's OIDC flow affecting versions 5.5.15 and prior. CVE-2025-66276 (CVSS 9.8) is a critical command injection in QNAP QTS, fixed in version 5.2.7.3256. CVE-2026-53838 (CVSS 9.8) in OpenClaw allows paired nodes to confuse approval scope decisions during reconnection. CVE-2026-45833 (CVSS critical, no CVSS score) is a code injection in ChromaDB Python project. CVE-2026-12043 (CVSS 8.8) in the AWS Common Runtime aws-c-http library allows a malicious server to cause memory corruption on connecting clients via malformed HPACK dynamic table size updates.

Synthesized by Vypr AI
ShinyHunters Oracle Zero-Day Added to KEV · VYPR