- Critical NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability allowing DoS or RCE
- High-severity NGINX Gateway Fabric authenticated configuration injection flaw
- High-severity NGINX Gateway Fabric authenticated configuration injection flaw
- Critical NGINX ngx_http_v3_module vulnerability allowing DoS or RCE
ThreatNoir Afternoon Brief — June 18
Afternoon Review in IT Security — June 18, 2026
The afternoon security briefing for June 18, 2026 brings critical developments across infrastructure patching, compliance challenges, and mobile malware threats. Organizations face urgent decisions regarding out-of-band updates, third-party script management, and Android banking trojans targeting financial applications globally.
F5 Issues Out-of-Band Patches for Critical NGINX Vulnerabilities
Cybersecurity company F5 has released out-of-band security updates addressing multiple NGINX web server vulnerabilities, including two critical-severity flaws that could allow attackers to execute code on vulnerable systems. The emergency patches target CVE-2026-11311, CVE-2026-42055, CVE-2026-42530, and CVE-2026-50107. Given the critical nature of these flaws and the widespread deployment of NGINX in production environments, organizations should prioritize applying these patches immediately to prevent potential remote code execution attacks. Source: F5 issues out-of-band patches for critical NGINX vulnerabilities
The Scripts on Your Checkout Page Are Now a PCI DSS Problem
Third-party scripts running on e-commerce checkout pages have become a compliance liability under updated PCI DSS requirements. An independent PCI assessor evaluation reveals that modern checkout flows load dozens of third-party scripts—including analytics tags, tag managers, support widgets, and payment iframes—each representing a potential vector for attackers such as Magecart. The new PCI DSS v4.0.1 standards now demand explicit control and monitoring of these scripts, placing responsibility on merchants to validate and manage all code executing in customer browsers during payment processing. Organizations must implement comprehensive script governance to maintain compliance and protect cardholder data. Source: The Scripts on Your Checkout Page Are Now a PCI DSS Problem
Atlassian, Splunk Patch Critical Vulnerabilities
Splunk and Atlassian have released critical security patches addressing vulnerabilities in their respective products. Splunk patched an OS command injection vulnerability in AI Toolkit, while Atlassian fixed dozens of flaws in third-party dependencies across its product suite. The affected CVEs include CVE-2026-20265, CVE-2026-20266, CVE-2026-40175, CVE-2026-41293, CVE-2026-42043, CVE-2026-42264, CVE-2026-42584, CVE-2026-43512, and CVE-2026-43515. These patches underscore the ongoing supply chain risk posed by vulnerable third-party dependencies and the need for organizations to maintain current versions of enterprise software. Source: Atlassian, Splunk Patch Critical Vulnerabilities
Rokarolla Banking Trojan Targets 200 Applications
Security researchers have identified the Rokarolla banking trojan actively targeting over 200 applications on Android devices, including banking and cryptocurrency platforms. The malware enables operators to take control of infected devices and harvest sensitive information from victims, posing significant risk to financial institutions and their customers. The broad targeting scope and capability to extract credentials and transaction data make Rokarolla a substantial threat to mobile banking security globally. Source: Rokarolla Banking Trojan Targets 200 Applications
The convergence of infrastructure vulnerabilities, compliance pressures, and mobile malware threats demands immediate action from security teams. Organizations should prioritize patch deployment, audit third-party script dependencies, and enhance mobile threat detection capabilities to address today's threat landscape.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- MagecartThreat actor known for web skimming attacks
- Critical vulnerability in Axios (third-party dependency for Atlassian)
- Critical vulnerability in Axios (third-party dependency for Atlassian)
- Critical vulnerability in Axios (third-party dependency for Atlassian)
- Vulnerability in Apache Tomcat (third-party dependency for Atlassian)
- Vulnerability in Apache Tomcat (third-party dependency for Atlassian)
- Critical OS command injection in Splunk AI Toolkit
- Vulnerability in Netty (third-party dependency for Atlassian)
- Vulnerability in Apache Tomcat (third-party dependency for Atlassian)
- Medium-severity information disclosure in Splunk AI Toolkit
- RokarollaName of the banking trojan.