CISA stopped reliably sending KEV alerts.
We didn't.
CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.
KEV Intelligence Brief | June 17, 2026
Issued: Wednesday, June 17, 2026 Scope: 8 CVEs added to CISA's KEV catalog between June 9–16, 2026 Audience: Federal contractors, DevOps teams, security operations leaders
Deadline Watch: Critical Unauthenticated Exploits Already Past or Expiring This Week
Three of the eight entries carry patch deadlines that have already passed or expire within 48 hours of this brief. Federal agencies and covered contractors operating under BOD 26-04 are in violation if remediation has not been completed or formally documented.
CVE-2026-35273 (Oracle PeopleSoft Enterprise PeopleTools) carried a deadline of June 15 — two days ago. This is a missing authentication for critical function vulnerability enabling complete system takeover without credentials. PeopleSoft deployments are routinely internet-facing in higher education, federal HR systems, and large enterprise ERP environments, making this a high-probability target for opportunistic ransomware staging and data exfiltration. If your organization has not patched, isolated, or formally accepted risk under BOD 26-04, you are overdue. Immediate isolation from the public internet is the minimum acceptable interim control.
CVE-2026-10520 (Ivanti Sentry, formerly MobileIron Sentry) had a patch deadline of June 14 — three days ago. The vulnerability enables unauthenticated remote code execution at root level via OS command injection. Ivanti products have been a persistent target for state-sponsored actors over the past several years, and Sentry's role as a mobile device management gateway means exploitation can provide direct access to corporate email, VPN credentials, and device management infrastructure. Any Sentry instance not yet patched should be treated as potentially compromised. Rotate credentials for all integrated systems, pull forensic triage artifacts per BOD 26-04 requirements, and do not reconnect to production until indicators of compromise are cleared.
CVE-2026-48907 (Widget Factory Joomla Content Editor) was added to the KEV on June 16 with a deadline of June 19 — this brief publishes two days before that window closes. The improper access control vulnerability permits unauthenticated users to create editor profiles and upload arbitrary PHP files, achieving remote code execution. Web content management systems are high-value targets precisely because they sit on public infrastructure with broad attack surface and inconsistent patch cadence. Administrators should immediately disable the Joomla Content Editor plugin if patching is not feasible before Friday, audit server logs for unexpected PHP file creation events, and review web shell detection rules.
Network Infrastructure Under Compound Pressure: Cisco and Arista
Two Cisco entries and one Arista entry were added during this cycle, presenting a compounding risk picture for organizations relying on SD-WAN and network operating systems at scale.
CVE-2026-20262 (Cisco Catalyst SD-WAN Manager) is a path traversal vulnerability that allows an authenticated remote attacker to create or overwrite arbitrary files on the system filesystem. Its patch deadline is June 29, giving teams slightly more runway, but the authenticated precondition should not induce complacency — credential compromise in SD-WAN management planes is well-documented and often precedes this class of exploit. Treat this as a two-stage threat: if your SD-WAN Manager credentials have been exposed through phishing, password reuse, or a prior breach, this CVE becomes unauthenticated in practice. Rotate administrative credentials now and restrict management plane access to out-of-band networks or MFA-enforced jump hosts.
CVE-2026-20245 (Cisco Catalyst SD-WAN Manager, same platform) was added June 9 with a deadline of June 23. This improper encoding/escaping vulnerability allows an authenticated local attacker to execute arbitrary commands as root via a crafted file. The simultaneous presence of two KEV-listed vulnerabilities in Cisco Catalyst SD-WAN Manager represents a chained exploitation risk — lateral movement or privilege escalation scenarios become considerably more tractable when both are unpatched. Network operations teams should treat the June 23 deadline as firm and apply the consolidated Cisco advisory covering both CVEs in a single maintenance window.
CVE-2026-7473 (Arista Extensible Operating System) adds a third network-layer concern with a June 23 deadline. The incomplete comparison vulnerability causes EOS switches to incorrectly decapsulate and forward unexpected tunneled packets matching the configured decapsulation IP. In practice, this can be abused to bypass network segmentation controls and route traffic through boundaries it should never cross. For organizations using Arista EOS in data center spine-leaf or cloud interconnect topologies, this is a segmentation integrity issue as much as a device-level vulnerability. Audit tunnel decapsulation configurations and validate east-west traffic inspection controls while patches are applied.
Browser Engines and Shared Hosting: Broad-Surface Exploitation Vectors
CVE-2026-11645 (Google Chromium V8), added June 9 with a June 23 deadline, involves out-of-bounds read and write in the V8 JavaScript engine, enabling arbitrary code execution inside the sandbox via crafted HTML. The critical operational note: this vulnerability affects any browser built on Chromium, explicitly including Microsoft Edge and Opera in addition to Chrome. Enterprise teams that manage browser policy through endpoint management platforms should push updates fleet-wide and not wait for organic user-initiated updates. BOD 22-01 applies for federal agencies; confirm patch status through your EDR or UEM telemetry rather than relying on self-reporting.
CVE-2026-54420 (LiteSpeed cPanel Plugin) rounds out the catalog with a symlink following vulnerability in a shared hosting context, carrying a deadline of June 18 — tomorrow. Users with FTP or web shell access on CloudLinux/CageFS-protected shared hosting servers can exploit symlink resolution to escape filesystem restrictions. Managed hosting providers and web hosting resellers carrying this plugin are the primary exposure. The low barrier to exploitation — requiring only existing FTP credentials — means this will likely be exploited by low-sophistication actors alongside more targeted campaigns. Update immediately or disable the LiteSpeed cPanel plugin; notify affected tenants of potential CageFS bypass exposure.
Summary Deadline Table
| CVE | Product | Deadline | Status | |---|---|---|---| | CVE-2026-10520 | Ivanti Sentry | June 14 | Overdue | | CVE-2026-35273 | Oracle PeopleSoft | June 15 | Overdue | | CVE-2026-54420 | LiteSpeed cPanel Plugin | June 18 | Tomorrow | | CVE-2026-48907 | Widget Factory Joomla CE | June 19 | 2 days | | CVE-2026-20245 | Cisco SD-WAN Manager | June 23 | 6 days | | CVE-2026-11645 | Google Chromium V8 | June 23 | 6 days | | CVE-2026-7473 | Arista EOS | June 23 | 6 days | | CVE-2026-20262 | Cisco SD-WAN Manager | June 29 | 12 days |
Sources: CISA KEV Catalog · CISA BOD 26-04 · Cisco Security Advisories · Oracle Critical Patch Update · Ivanti Security Advisories · Google Chrome Releases · Arista Security Advisories · CISA BOD 22-01
Free KEV Alerts
- Real-time notification the moment a KEV drops
- Vendor and product details
- BOD 26-04 remediation deadline included
Pro Alerts Coming Soon
- Real-time notification the moment a KEV drops
- Filtered to your specific vendor watchlist
- Urgency scoring (Critical / Urgent / Standard)
- Direct patch links included
Stay ahead of CISA.
Common Vulnerability and Exposure
CVEs form a database of known security vulnerabilities that are actively tracked and managed by a group of organizations, such as the U.S. National Cyber Security Alliance. CVEs are an important tool for network security management because they not only provide an inventory of existing vulnerabilities, but also provide information about how the vulnerability can be exploited and instructions on how to protect against it.
Search the KEV Catalog by Vendor or Product
Search for CVEs by vendor or product to identify known exploited vulnerabilities in your environment
Upcoming Patch Due Dates
via Binding Operational Directive 26-04
BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.
Loading...
Cyber Security News
You may have missed...
*
Inside a cyberattack: How hackers steal data
The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...
China-Linked Hackers Stole Data For More Than A Year - Silicon UK
The hackers sought materials related to defence intelligence, military strategy in the Indo-Pacific region, AI, unmanned vehicles, cyber warfare ...
China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth
Cybersecurity researchers have flagged two previously undocumented Windows variants of what was believed to be a Linux-only backdoor called SprySOCKS.
Can computer hackers get inside your mind? | NCPR News
On today's show: a whodunit about hackers, 'Cyber Paleontologists', spy-vs-spy protocols, cryptic intelligence leaks, nuclear physics, high-precision ...
'Dangerous' AI Models Are Coming No Matter What | WIRED
The US government crackdown on Anthropic's Claude Fable 5 and Mythos 5 hides a glaring truth: AI models with advanced hacking capabilities will ...
Trump's Anthropic crackdown rattles cyber defenders - Axios
AI researchers and cybersecurity leaders fear the U.S. government is setting a precedent that may discourage American AI companies from building ...
CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting Widget Factory Joomla ...
China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth
ESET researchers discovered two previously undocumented Windows variants of the SprySOCKS backdoor used by China-aligned FishMonger group, featuring k...
AUR Supply Chain Attack: 400+ Arch Packages Backdoored with Rootkit and Infostealer
An AUR supply chain attack compromised over 400 Arch Linux packages starting June 11, 2026, planting a Rust-based credential stealer and an eBPF rootk...
Updated daily
