1. Top Action Item

Patch or mitigate the actively exploited unauthenticated RCE in Alibaba's Fastjson 1.x library (CVE-2026-16723, CVSS 9.0) if you run Java/Spring Boot applications that process JSON. No vendor patch exists; apply workarounds from security vendors (ThreatBook, Imperva) such as upgrading to Fastjson 2.x or implementing strict JSON input validation. Also prioritize applying the GitLab 18.11.3 update from June 10 to prevent unauthenticated RCE via Jupyter notebook payloads, now that public exploit code is circulating.


2. Exploited This Week

Fastjson 1.x — CVE-2026-16723 (Critical, CVSS 9.0)

PTC Windchill / FlexPLM (unauthenticated RCE, no CVE given)

Zimbra Webmail (zero-day, no CVE given)


3. Critical Patch Roundup

GitLab CE/EE (RCE)

Chromium Browser Engines (CVEs: CVE-2026-16807, CVE-2026-16806, CVE-2026-16805, CVE-2026-16804)

OpenAI ChatGPT Workspace Agents — AgentForger

Microsoft Bing Images (CVEs: CVE-2026-32194, CVE-2026-???)

Active Directory — Certighost (certificate impersonation)

Azure Automation — cross-tenant identity takeover

Azure AI Search — CVE-2026-56167 (SSRF -> EoP)

Azure Kubernetes Service — CVE-2026-56163 (EoP)

Microsoft Account RCE — CVE-2026-56165


4. Home / SOHO Impact


5. Enterprise Impact


6. What To Patch First

  1. Fastjson 1.x — CVE-2026-16723 (exploited in the wild, critical, no patch — apply workarounds)
  2. PTC Windchill / FlexPLM (exploited in the wild, critical — apply vendor patch)
  3. Zimbra Webmail (exploited in the wild — apply vendor patch)
  4. GitLab CE/EE — v18.11.3 (PoC published, widely deployed enterprise software)
  5. Google Chrome / Microsoft Edge — latest version (critical Chromium CVEs, widely deployed)
  6. Azure AI Search — CVE-2026-56167 (critical, cloud service)
  7. Azure Kubernetes Service — CVE-2026-56163 (critical, cloud service)
  8. Active Directory certificate services — monitor for Certighost (no patch, but urgent detection)

Sources