VORANT. Threat Intelligence Sign in Get the full feed

CERT-FR flags exploited Ivanti, Oracle, CheckPoint flaws

high vulnerability technologyinfrastructure

France's CERT-FR highlights actively exploited critical vulnerabilities in Ivanti Sentry, Oracle PeopleSoft, CheckPoint firewalls, and Google Chrome from the week of 8–14 June 2026.

The French national CERT (CERT-FR) published its weekly threat bulletin covering significant vulnerabilities disclosed between 8 and 14 June 2026. The advisory highlights four actively exploited critical flaws: CVE-2026-10520 (CVSS 10.0) in Ivanti Sentry enabling remote code execution, CVE-2026-35273 (CVSS 9.8) in Oracle PeopleSoft also allowing RCE, CVE-2026-50751 (CVSS 9.3) in CheckPoint Security Gateways and Spark Firewalls permitting security-policy bypass, and CVE-2026-11645 (CVSS 8.8) in Google Chrome leading to RCE. Public exploit code exists for a second Ivanti Sentry vulnerability (CVE-2026-10523, CVSS 9.9) and for flaws in Splunk Enterprise/Cloud Platform (CVE-2026-20253) and FreeBSD (CVE-2026-49413).

The bulletin also catalogues dozens of additional high-severity CVEs across Microsoft Windows/Edge/Azure, SAP NetWeaver, Adobe ColdFusion, Apache HTTP Server, IBM WebSphere, Fortinet FortiSandbox, and other enterprise platforms, though these lack public evidence of exploitation. CERT-FR further references older but still-exploited vulnerabilities in Palo Alto PAN-OS (CVE-2024-3400), Ubiquiti UniFi OS (CVE-2026-34910), and LiteLLM (CVE-2026-42271), reinforcing the persistent threat from unpatched systems. The advisory underscores the urgency of applying vendor patches for all listed issues, particularly the four confirmed in-the-wild exploits.

Mentioned in this report

Vulnerabilities CVE-2024-3400KEVCVE-2025-68121CVE-2026-10520KEVCVE-2026-10523CVE-2026-10879CVE-2026-11645KEVCVE-2026-12027CVE-2026-20253KEVCVE-2026-25089KEVCVE-2026-26142CVE-2026-27671CVE-2026-29167CVE-2026-34910KEVCVE-2026-35273KEVCVE-2026-42271KEVCVE-2026-42897KEVCVE-2026-44631CVE-2026-44748CVE-2026-44815CVE-2026-44963CVE-2026-45657CVE-2026-47291CVE-2026-47643CVE-2026-47928CVE-2026-49413CVE-2026-50751KEVCVE-2026-7473KEVCVE-2026-8633

Source reporting: https://www.cert.ssi.gouv.fr/actualite/CERTFR-2026-ACT-026/

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free