---
schema: 1
kind: vulnerability
title: "CVE-2026-47344 et al. — TYPO3 core June release: 13 CVEs across every supported branch (10.4 ELTS → 14.3 LTS)"
headline: "CVE-2026-47344 et al. — TYPO3 core June release: 13 CVEs across every supported branch (10.4 ELTS → 14.3 LTS)"
summary: "TYPO3 published 13 advisories on 8 June (TYPO3-CORE-SA-2026-006 onward) covering XSS bypassing the HTML Sanitizer, authenticated RCE, privilege escalation, open redirect and other security-restriction bypasses, fixed in 10.4.57/11.5.51/12.4.46 ELTS, 13.4.31 LTS and 14.3.3 LTS (TYPO3, 2026-06-08)."
discovered_at: "2026-06-10T05:00:11Z"
event_date: 2026-06-09
run_id: 2026-06-10-c84347b2
priority: notable
immediate_action: null
tags:
  - vulnerabilities
  - rce
  - priv-esc
regions:
  - dach
  - europe
sectors:
  - public-sector
entities: []
cves:
  - id: CVE-2026-47344
    cvss: n/a
    epss: null
    type: rce
    vector: user-interaction
    auth: post-auth
    status:
      - patch-available
sources:
  - url: "https://typo3.org/security/advisory/typo3-core-sa-2026-006"
    publisher: "TYPO3, 2026-06-08"
    role: primary
  - url: "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1835"
    publisher: "BSI CERT-Bund, 2026-06-09"
    role: corroborating
closed_sources: []
evidence: []
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions: []
migrated_from: briefs/2026-06-10.md
---

TYPO3 published 13 advisories on 8 June (TYPO3-CORE-SA-2026-006 onward) covering XSS bypassing the HTML Sanitizer, authenticated RCE, privilege escalation, open redirect and other security-restriction bypasses, fixed in 10.4.57/11.5.51/12.4.46 ELTS, 13.4.31 LTS and 14.3.3 LTS ([TYPO3, 2026-06-08](https://typo3.org/security/advisory/typo3-core-sa-2026-006)). BSI CERT-Bund catalogued the batch as WID-SEC-2026-1835 (HIGH) ([BSI CERT-Bund, 2026-06-09](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1835)). TYPO3 is the dominant CMS for German-speaking public-sector web estates (federal ministries, cantonal/municipal portals, universities across DACH), and the version span means essentially every production install carries at least one of these CVEs. No active exploitation reported; the higher-impact vectors require authentication. ELTS-branch operators need a subscription for fixes — those without one should accelerate migration to 13.4 LTS / 14.3 LTS.


#### CVE Summary Table

| CVE | Product | CVSS | EPSS | KEV | Exploited | Patch | Source |
|---|---|---|---|---|---|---|---|
| CVE-2026-10520 | Ivanti Sentry (MICS API) | 10.0 | n/a | No | No (public PoC) | R10.5.2/R10.6.2/R10.7.1 | [watchTowr](https://labs.watchtowr.com/more-evidence-that-words-dont-mean-what-we-thought-they-meant-ivanti-sentry-pre-auth-os-command-injection-cve-2026-10520/) |
| CVE-2026-47291 | Windows HTTP.sys (IIS/WinRM) | 9.8 | n/a | No | No ("More Likely") | June 2026 Patch Tuesday | [MSRC](https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-47291) |
| CVE-2026-44815 | Windows DHCP Client | 9.8 | n/a | No | No | June 2026 Patch Tuesday | [Tenable](https://www.tenable.com/blog/microsofts-june-2026-patch-tuesday-addresses-198-cves-cve-2026-49160-cve-2026-50507) |
| CVE-2026-44748 | SAP NetWeaver AS ABAP (SAML) | 9.9 | n/a | No | No | SAP June Patch Day | [Onapsis](https://onapsis.com/blog/sap-security-patch-day-june-2026) |
| CVE-2026-27671 | SAP NetWeaver/ABAP (RFC kernel) | 9.8 | n/a | No | No | SAP Note 3717897 | [Onapsis](https://onapsis.com/blog/sap-security-patch-day-june-2026) |
| CVE-2026-47895 | strongSwan libstrongswan | n/a | n/a | No | No | strongSwan 6.0.7 | [strongSwan](https://www.strongswan.org/blog/2026/06/08/strongswan-vulnerability-(cve-2026-47895).html) |
| CVE-2026-44963 | Veeam Backup & Replication 12.x | 9.4 | n/a | No | No | 12.3.2.4854 | [Veeam](https://www.veeam.com/kb4869) |
| CVE-2026-11645 | Chrome / Chromium V8 | 8.8 | n/a | Yes | Yes | Chrome 149.0.7827.103 | [Chrome](https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html) |
| CVE-2026-7473 | Arista EOS (VXLAN/GRE decap) | n/a | n/a | Yes | Yes | Per Arista SA-0137 | [Arista](https://www.arista.com/en/support/advisories-notices/security-advisory/24005-security-advisory-0137) |
| CVE-2026-47344 | TYPO3 Core (SA-2026-006) | n/a | n/a | No | No | 13.4.31 / 14.3.3 | [TYPO3](https://typo3.org/security/advisory/typo3-core-sa-2026-006) |
