This month: 21 KEVs detected

CISA stopped reliably sending KEV alerts.
We didn't.

CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.

CVE-2025-67038
Lantronix · EDS5000
Lantronix EDS5000 Code Injection Vulnerability
Detected Jun 23 · 3-day patch deadline
CVE-2026-34908
Ubiquiti · UniFi OS
Ubiquiti UniFi OS Improper Access Control Vulnerability
Detected Jun 23 · 3-day patch deadline
CVE-2026-20253
Splunk · Enterprise
Splunk Enterprise Missing Authentication for Critical Function Vulnerability
Detected Jun 18 · 3-day patch deadline

KEV Intelligence Brief — June 24, 2026

Issued: Wednesday, June 23, 2026 | Scope: Federal Contractors, DevOps, Security Operations | Authority: CISA BOD 26-04

Three separate deadline clusters, eight confirmed-exploited vulnerabilities, and a consistent throughline: network-adjacent and unauthenticated attack paths dominating the threat landscape. This brief consolidates the most recent KEV additions and identifies where operational urgency is highest.

Deadline Watch: Network Infrastructure Under Active Pressure

The most time-critical entries in this cycle involve Ubiquiti UniFi OS and Lantronix EDS5000 — both carrying a patch deadline of June 26, 2026, meaning federal agencies and covered contractors have approximately 48 hours to act.

Three distinct CVEs affect Ubiquiti UniFi OS simultaneously, and they should be treated as a coordinated exploitation surface rather than isolated findings. CVE-2026-34908 (improper access control) allows network-adjacent actors to make unauthorized system changes. CVE-2026-34909 (path traversal) enables file access that can be leveraged to compromise underlying accounts. CVE-2026-34910 (improper input validation / command injection) closes the loop by providing code execution capability. Together, these three vulnerabilities form a credible chained attack path: gain a foothold via access control bypass, traverse to sensitive files, and execute commands. Organizations running UniFi OS in environments with flat or poorly segmented networks are particularly exposed. If patching cannot be completed before June 26, isolate UniFi controllers from untrusted network segments and audit authentication logs for anomalous administrative activity.

CVE-2025-67038 in the Lantronix EDS5000 — a serial device server commonly deployed in OT and industrial environments — is arguably the most dangerous single entry in this batch. The vulnerability allows OS command injection via the username parameter, with injected commands executing at root privilege. This is a pre-authentication or low-friction attack against a device that often sits at the boundary between IT and operational technology networks. Internet-exposed EDS5000 units should be considered compromised until proven otherwise. Immediate action: pull these devices off public-facing segments, apply vendor firmware updates, and initiate forensic triage per CISA's BOD 26-04 requirements. If mitigations are unavailable, discontinue use — the risk posture of a root-level command injection on OT infrastructure cannot be tolerated during active exploitation.

Overdue: Web Platforms and Data Infrastructure Failures

Two entries in this batch have already passed their patch deadlines, meaning covered organizations are out of compliance as of today.

CVE-2026-48907 in the Widget Factory Joomla Content Editor carried a deadline of June 19, 2026 — five days ago. The vulnerability permits unauthenticated users to create new editor profiles and upload and execute arbitrary PHP code. This is effectively unauthenticated remote code execution on any internet-facing Joomla installation running the affected plugin. Web shells, lateral movement, and data exfiltration are the immediate downstream risks. If your organization has not patched, assume the affected host is compromised: pull it from production, conduct forensic review of file system changes and new user profiles created in the past 30 days, and rotate all credentials stored or accessible on that host.

CVE-2026-20253 in Splunk Enterprise had a deadline of June 21, 2026 — also now overdue. A missing authentication vulnerability exposes a PostgreSQL sidecar service endpoint to unauthenticated file creation and truncation. For Splunk deployments, this is particularly consequential: arbitrary file writes can be used to corrupt index configurations, plant backdoors in search scripts, or disable logging integrity — directly undermining the security monitoring function Splunk is deployed to provide. Splunk administrators should verify endpoint exposure, apply the patch immediately, and audit recent file system activity on the Splunk host for anomalous writes.

Managed Infrastructure: Shared Hosting and SD-WAN Exposure

The final two KEV entries target managed hosting and enterprise WAN infrastructure — environments that often receive less aggressive patch scrutiny because they sit beneath abstraction layers.

CVE-2026-54420 in the LiteSpeed cPanel Plugin (deadline: June 18, 2026, now overdue) exploits a UNIX symlink-following vulnerability in shared hosting environments running CloudLinux/CageFS. An attacker with FTP or web shell access can escape the CageFS container boundary — precisely the isolation mechanism these environments rely on to separate tenants. For managed hosting providers, this represents a cross-tenant compromise risk. Hosting operators should prioritize patching and audit CageFS integrity, reviewing symlink configurations and any accounts with recent FTP or shell activity.

CVE-2026-20262 in Cisco Catalyst SD-WAN Manager has the most generous deadline in this batch — June 29, 2026 — but warrants immediate attention. An authenticated remote attacker can leverage a path traversal flaw to create or overwrite arbitrary files on the filesystem. In SD-WAN environments, file overwrites can manipulate routing policy, VPN configurations, or logging, with enterprise-wide network consequences. While the authentication requirement raises the bar slightly, compromised credentials — a routine occurrence — eliminate that barrier entirely. Cisco SD-WAN operators should apply patches before June 29, enforce strict MFA on management interfaces, and review filesystem integrity logs for unexpected file modifications.

Summary Posture

| CVE | Product | Deadline | Status | |---|---|---|---| | CVE-2026-54420 | LiteSpeed cPanel Plugin | June 18 | Overdue | | CVE-2026-48907 | Joomla Content Editor | June 19 | Overdue | | CVE-2026-20253 | Splunk Enterprise | June 21 | Overdue | | CVE-2026-20262 | Cisco Catalyst SD-WAN Manager | June 29 | Imminent | | CVE-2025-67038 | Lantronix EDS5000 | June 26 | 48 hrs | | CVE-2026-34908/09/10 | Ubiquiti UniFi OS | June 26 | 48 hrs |

All eight CVEs carry BOD 26-04 obligations for federal agencies and covered contractors. Organizations that cannot patch within deadlines must document compensating controls, assess internet exposure of each affected asset, and satisfy CISA's forensic triage requirements.

Sources: CISA KEV Catalog · CISA BOD 26-04 · Cisco Security Advisories · Ubiquiti Security Advisory Portal · Splunk Security Advisories · Lantronix Support · LiteSpeed Security Notices

Free KEV Alerts

  • Real-time notification the moment a KEV drops
  • Vendor and product details
  • BOD 26-04 remediation deadline included

Pro Alerts Coming Soon

  • Real-time notification the moment a KEV drops
  • Filtered to your specific vendor watchlist
  • Urgency scoring (Critical / Urgent / Standard)
  • Direct patch links included

Stay ahead of CISA.

No spam. Unsubscribe anytime. We don't sell your data.


Upcoming Patch Due Dates

via Binding Operational Directive 26-04

BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.

Loading...

News Logo

Cyber Security News

You may have missed...


📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://thehackernews.comJun 24

FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation

... Hacker News. "The same pairs also appear in the actor's input target list EU.txt (the file their Go scanner reloads and re-validates every cycle ....

https://www.cbc.caJun 24

Five Eyes cybersecurity agencies warn of new AI models impact on cyber risks - CBC

Cutting-edge artificial intelligence technology is poised to supercharge offensive hacking ... Hacking concerns. The ⁠Monday statement from the Five ....

https://federalnewsnetwork.comJun 23

White House PQC order 'lights a fire' under post-quantum transition | Federal News Network

Cybersecurity experts are particularly concerned that U.S. adversaries could steal data today and decrypt using a quantum computer in the future ...

https://www.nytimes.comJun 24

N.S.A. Lost Access to Powerful A.I. Model Amid Anthropic Dispute - The New York Times

A recent episode underscored the Trump administration's increasing reliance on advanced A.I. systems for cybersecurity even as it battles a ...

https://industrialcyber.coJun 24

Dragos launches EmberAI to bring OT-native AI to industrial cybersecurity operations

Threat activity against critical infrastructure is accelerating. The OT cybersecurity skills needed to address these complex tactics and techniques .....

https://www.bbc.comJun 23

How 100 Romanian hospitals switched to pen and paper to defeat a national cyber-attack

Around the same time, Change Healthcare in the US was hacked, leading to widespread disruption. The company paid a $22m (£16m) ransom to hackers.

https://www.govinfosecurity.comJun 23

North Korean Hackers Poison Mastra AI Framework - GovInfoSecurity

Open-source artificial intelligence framework Mastra has been compromised by North Korean hackers who planted infostealers, adding yet another ...

https://ca.finance.yahoo.comJun 23

'Five Eyes' intelligence alliance warns that new AI models pose urgent cyber risk

By Raphael Satter WASHINGTON, June 22 (Reuters) - Cutting-edge artificial intelligence technology is poised to supercharge offensive hacking ...


Updated daily