Isometric network nodes highlighting CISA warnings and AI agent attack vectors.

Daily Cybersecurity News - June 19, 2026

CISA Adds Splunk Flaw to KEV List

CISA added a Splunk Enterprise flaw to its known-exploited list and told agencies to patch by Sunday.

CVE-2026-20253 lets remote attackers reach a sensitive endpoint without credentials. CVSS 9.8 and actively exploited in the wild.

Affects Splunk Enterprise 10.2.0-10.2.3 and 10.0.0-10.0.6. Splunk Cloud is not affected (the vulnerable PostgreSQL sidecar isn't used there); on-prem only.

Patches have been available since June 10, in Splunk 10.2.4 and 10.0.7.

AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution

A single malicious webpage can hijack an AI browsing agent and run arbitrary code on the host machine.

Microsoft researchers detail the AutoJack chain. The agent visits the attacker page, then its JavaScript reaches a privileged local service and spawns a reverse shell. No CVE assigned yet.

Affects Microsoft's AutoGen Studio specifically, and only its development builds with MCP support, the PyPI release was never exposed, and Microsoft fixed it the same day.

Researchers reproduced the full chain on a default Windows 11 install with the agent running as the logged-in user.

F5 Patches Two Critical NGINX Flaws

F5 patched two critical flaws in NGINX Open Source that let unauthenticated attackers reach remote code execution on misconfigured servers.

CVE-2026-42530 is a use-after-free in the ngx_http_v3_module triggered by crafted HTTP/3 sessions. CVE-2026-42055 is a heap buffer overflow in ngx_http_proxy_v2_module and ngx_http_grpc_module when proxying HTTP/2 with ignore_invalid_headers off and large_client_header_buffers over 2 MB. Both score CVSS 9.2.

NGINX Open Source 1.31.0 through 1.31.1 and 1.30.0 through 1.30.2 are affected, plus NGINX Plus, Gateway Fabric, and Ingress Controller builds using those versions.

Patches landed in Open Source 1.31.2 and 1.30.3.

CISA Warns Fortinet Users After FortiBleed Leak

CISA told Fortinet customers to lock down exposed firewalls and VPNs after nearly 74,000 credentials appeared online.

The leak, called FortiBleed, included admin passwords and config files for devices still reachable from the internet. Attackers grabbed the data from misconfigured management interfaces.

Most of the exposed devices sat on the public internet with weak protections. The volume suggests a broad scan rather than a targeted breach.

CISA issued a hardening advisory: reset credentials, terminate sessions, enforce MFA. It added nothing to the KEV catalog; FortiBleed is a credential leak, not a CVE.