Weekly Threat Brief: Old Bugs, New Exploits

Published: June 8, 2026

Week Ending: June 7, 2026 | Overall Risk Posture: Elevated

The week ending June 7 was not defined by one single blockbuster vulnerability. It was defined by something more operationally uncomfortable: old bugs, exposed services, and overlooked infrastructure moving back into the active exploitation queue.

CISA added five vulnerabilities to the Known Exploited Vulnerabilities catalog this week. The additions affected Oracle WebLogic Server, the Linux kernel, Android Framework, Mirasvit Full Page Cache Warmer for Magento 2, and SolarWinds Serv-U.

The affected technologies sit in very different places: enterprise middleware, container hosts, mobile devices, e-commerce platforms, and managed file-transfer systems. But they share one common lesson. Attackers are not only chasing brand-new vulnerabilities. They are also testing whether organizations still have reachable, under-patched, or poorly owned systems sitting in the environment.

Threat at a Glance

Threat Area Key Issue Why It Matters Defender Priority
Enterprise Middleware Oracle WebLogic Server was added to KEV for CVE-2024-21182. WebLogic often supports business-critical Java applications and can remain exposed long after patches are released. Patch affected systems, restrict T3/IIOP exposure, and review internet-facing WebLogic instances.
Linux and Containers Linux Kernel CVE-2022-0492 returned as an active exploitation signal. The bug affects the cgroups v1 release_agent feature and is especially relevant to older Linux hosts and containerized environments. Validate kernel patching, cgroups v1 exposure, privileged containers, and container-host hardening.
Mobile Devices Android Framework CVE-2025-48595 was added to KEV. Google noted indications of limited, targeted exploitation, making this more important for high-risk users and managed Android fleets. Push June 2026 Android security updates and identify devices delayed by OEM or carrier update schedules.
E-commerce Platforms Mirasvit Full Page Cache Warmer for Magento 2 was added for CVE-2026-45247. A third-party Magento extension can become a production compromise path when it processes unauthenticated traffic. Update to a fixed version, review CacheWarmer cookie activity, and check for web shells or unauthorized changes.
File Transfer Infrastructure SolarWinds Serv-U was added for CVE-2026-28318. Even denial-of-service exploitation can disrupt business-critical file exchange and partner workflows. Apply Serv-U 15.5.4 Hotfix 1 or vendor mitigations and monitor for repeated service crashes.

Active Exploitation and Immediate Risk

  • Oracle WebLogic showed that old enterprise middleware remains alive in the attack surface
    On June 1, CISA added CVE-2024-21182 to the Known Exploited Vulnerabilities catalog. The vulnerability affects Oracle WebLogic Server and can allow an unauthenticated attacker with network access through T3 or IIOP to compromise the server.

    The important point is not simply that WebLogic appeared again. The important point is that a vulnerability addressed in Oracle’s July 2024 Critical Patch Update became a 2026 exploitation priority. That is the pattern defenders should notice. Attackers do not need new vulnerabilities when old middleware remains exposed, difficult to patch, or poorly inventoried.

    For defenders, the response should start with externally reachable WebLogic servers, especially systems where T3 or IIOP is available from untrusted networks. Internet exposure, legacy application ownership, and incomplete patch records should move this issue ahead of ordinary backlog items.
  • Linux CVE-2022-0492 brought container escape risk back into focus
    On June 2, CISA added CVE-2022-0492, a Linux kernel vulnerability involving the cgroups v1 release_agent feature. The issue can allow privilege escalation where affected conditions exist.

    This is especially relevant for containerized environments because cgroups are part of the machinery used to isolate workloads. The vulnerability itself is not new. It was originally disclosed years ago. The renewed KEV signal matters because exploitation is no longer only theoretical.

    Security teams should not treat this as a generic Linux patching task. They should check where cgroups v1 is still in use, which container hosts are running older kernels, whether privileged containers exist, and whether container runtime hardening is actually enforced. In many environments, container-host patching is less visible than ordinary server patching because ownership is split between platform, infrastructure, and application teams.
  • Android CVE-2025-48595 signaled targeted mobile exploitation
    CISA also added CVE-2025-48595 on June 2. Google’s June 2026 Android Security Bulletin noted indications that the issue may be under limited, targeted exploitation. The flaw affects the Android Framework and is listed as a high-severity elevation-of-privilege issue.

    The practical impact is not the same for every organization. For most users, the answer is simple: install the June Android security update when available. For organizations with executives, administrators, legal teams, security staff, journalists, or other high-risk users, the issue deserves faster handling.

    Mobile exploitation often appears narrow at first. That does not make it irrelevant. Targeted mobile compromise can expose identity tokens, email, messaging, MFA prompts, cloud sessions, and sensitive communications. Defenders should confirm patch availability across managed Android fleets and identify devices that cannot yet receive the June patch level because of OEM or carrier update delays.
  • Mirasvit Cache Warmer turned a Magento extension into an RCE risk
    On June 3, CISA added CVE-2026-45247, affecting Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12. The vulnerability involves unsafe deserialization through the CacheWarmer cookie and can allow unauthenticated remote code execution.

    This is the kind of vulnerability that can be underestimated because it sits in an extension rather than the core platform. That is a mistake. E-commerce extensions often run inside production storefronts, process unauthenticated traffic, and sit close to customer accounts, administrator sessions, order data, payment-adjacent workflows, and operational reporting.

    Defenders should update the extension, review web application logs for suspicious CacheWarmer cookie activity, inspect for new or modified files, and check whether web shells or persistence mechanisms were placed after exploitation. For Magento and Adobe Commerce environments, extension inventory should be treated as part of the critical attack surface, not as a side list.
  • SolarWinds Serv-U showed why file-transfer systems remain sensitive infrastructure
    On June 5, CISA added CVE-2026-28318, a SolarWinds Serv-U uncontrolled resource consumption vulnerability. The issue allows unauthenticated specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service.

    This is a denial-of-service vulnerability, not a remote-code-execution issue. But that does not make it low priority. Managed file-transfer systems are often externally reachable, business-critical, and tied to partners, customers, finance workflows, legal exchanges, or operational data movement.

    The risk is availability, but the operational impact can still be serious. If Serv-U is used for scheduled file exchange or partner data transfer, repeated crashing can interrupt business processes and create incident-response noise. Organizations should apply Serv-U 15.5.4 Hotfix 1 or follow SolarWinds mitigation guidance where immediate patching is not possible.

Common Failure Patterns

  • Old patches are still becoming new incidents
    WebLogic and Linux kernel entries show that old vulnerabilities do not age out of attacker interest when exposed systems remain reachable. Vulnerability age is not a reliable risk reducer. If the system is exposed, useful, and unpatched, it can still become part of an active exploitation chain.
  • Specialized systems are often under-inventoried
    File-transfer servers, Magento extensions, container hosts, mobile fleets, and middleware platforms may not be tracked with the same discipline as endpoints or cloud workloads. That creates blind spots when KEV additions land.
  • Internet-facing infrastructure still carries outsized risk
    WebLogic, Mirasvit/Magento, and Serv-U all matter because they can sit near the public edge. When exploitation is confirmed, exposure becomes more important than theoretical severity alone.
  • Mobile patching remains uneven
    Android security updates depend on device model, manufacturer, carrier, and mobile-device-management policy. A patch may exist before it is actually deployed across the fleet. That gap matters most for high-risk users.
  • Container security depends on host hygiene
    Runtime controls help, but they do not replace kernel patching, cgroups configuration review, restrictions on privileged containers, and strong isolation between workloads. A container program is only as strong as the hosts underneath it.

Defender Priorities

  • Patch or isolate Oracle WebLogic systems affected by CVE-2024-21182
    Prioritize internet-facing instances and systems where T3 or IIOP is reachable from untrusted networks. Review logs for suspicious access attempts, unexpected authentication events, unusual application behavior, and unexplained access to sensitive data.
  • Validate Linux kernel exposure to CVE-2022-0492
    Identify container hosts, legacy Linux systems, and environments using cgroups v1. Confirm kernel fixes are applied and review whether privileged containers, weak namespace isolation, or permissive container runtime settings could increase impact.
  • Push Android June 2026 security updates
    Prioritize managed devices used by executives, administrators, legal teams, security staff, and other high-risk users. Track devices that cannot yet receive the June patch level and consider compensating controls for sensitive roles.
  • Update Mirasvit Full Page Cache Warmer for Magento
    Move affected Magento 2 deployments to version 1.11.12 or later. Review HTTP logs for suspicious CacheWarmer cookie values and investigate for web shells, modified files, unauthorized admin activity, or unusual outbound connections.
  • Patch SolarWinds Serv-U or apply vendor mitigations
    Upgrade to Serv-U 15.5.4 Hotfix 1 where applicable. If patching is delayed, restrict access, apply available filtering guidance, and monitor for repeated service crashes or crafted POST requests using the Content-Encoding: deflate header.
  • Use KEV as an exposure trigger, not just a patch list
    For each addition, ask three simple questions: is it exposed, is it business-critical, and is ownership clear? If the answer is uncertain, the risk is higher than the CVE description alone suggests.
  • Separate remediation by asset class
    This week’s additions do not belong to one team. Middleware, Linux hosts, mobile devices, Magento extensions, and file-transfer systems may sit under different owners. Assign remediation ownership clearly before assuming the patch process is underway.

Signals to Watch

  • Enterprise middleware remains a durable target
    WebLogic continues to appear in real-world exploitation because it is widely deployed, difficult to replace, and often tied to legacy business applications. These systems may remain exposed because they are old enough to be forgotten but important enough that no one wants to touch them.
  • Container hosts are becoming part of vulnerability-management reality
    Security teams cannot separate container risk from Linux host risk. Kernel flaws still matter inside modern platform environments, especially when old hosts, privileged containers, or cgroups v1 remain in use.
  • E-commerce extensions deserve production-level scrutiny
    A third-party Magento extension can create the same practical exposure as a core platform bug when it processes unauthenticated web traffic. Extension inventory, version tracking, and emergency patching need to be part of the storefront security process.
  • Mobile exploitation is usually quiet before it is broad
    Limited targeted exploitation should still matter to organizations with high-value users and sensitive communications. Mobile devices often hold the same identity and communication access as laptops, but they are not always managed with the same urgency.
  • Availability bugs can still become operational incidents
    Serv-U shows that not every KEV addition needs to enable code execution to be urgent. Business-critical systems can be attacked through disruption as well as compromise.

Weekly Pulse

The week ending June 7 produced a clear message: exploitation pressure is moving wherever organizations have delayed visibility.

Oracle WebLogic represented legacy enterprise middleware. Linux CVE-2022-0492 represented old kernel risk returning through container and host exposure. Android CVE-2025-48595 represented targeted mobile exploitation. Mirasvit represented e-commerce extension risk. SolarWinds Serv-U represented business-critical file-transfer infrastructure.

These are different categories, but the defender lesson is the same. Attackers are not only chasing new zero-days. They are also testing whether organizations actually know where their older, specialized, exposed, or operationally sensitive systems are.

Bottom Line

This week’s CISA KEV changes were not dominated by one vendor or one technology class. They showed exploitation across the systems that often fall between ownership boundaries: middleware, Linux hosts, mobile devices, e-commerce extensions, and file-transfer services.

For defenders, the priority is clear: patch WebLogic, validate Linux and container-host exposure, push Android updates, update Mirasvit Cache Warmer, and protect SolarWinds Serv-U. But the larger lesson is broader than any one CVE.

KEV is not just a list of exploited vulnerabilities. It is a map of where attackers are finding operational gaps. This week, those gaps were old patches, exposed services, third-party extensions, mobile update delays, and business-critical systems that may not sit cleanly inside a single team’s patching process.

The risk is not only what is vulnerable. The risk is what is still reachable, still trusted, and still not owned.

Support independent security analysis

If you find ByteVanguard useful, you can support the site and help keep the analysis independent.

Support the analysis
Intelligence over headlines. Signal over noise.

Stay Connected

Report Intelligence
© 2026 ByteVanguard. Built for security professionals.