This month: 17 KEVs detected

CISA stopped reliably sending KEV alerts.
We didn't.

CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.

CVE-2026-20253
Splunk · Enterprise
Splunk Enterprise Missing Authentication for Critical Function Vulnerability
Detected Jun 18 · 3-day patch deadline
CVE-2026-48907
Widget Factory · Joomla Content Editor
Widget Factory Joomla Content Editor Improper Access Control Vulnerability
Detected Jun 16 · 3-day patch deadline
CVE-2026-54420
LiteSpeed · cPanel Plugin
LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability
Detected Jun 15 · 3-day patch deadline

KEV Intelligence Brief — June 19, 2026

Prepared for: Federal Contractors · DevOps Teams · Security Operations Leaders Classification: Unclassified // For Official Distribution

Eight vulnerabilities added to CISA's KEV catalog over the past ten days present an unusually dense concentration of unauthenticated attack paths, infrastructure management plane exposures, and overdue patch deadlines. Several deadlines have already passed as of today. Teams should treat this brief as an immediate action item, not a planning document.

Critical Deadlines Already Passed — Assume Compromise, Begin Forensic Triage

Four of the eight entries carried patch deadlines that have already elapsed, and in each case the vulnerability class warrants escalation beyond routine patching.

CVE-2026-10520 (Ivanti Sentry) had a deadline of June 14. An OS command injection flaw in the former MobileIron Sentry gateway allows a remote, unauthenticated attacker to achieve root-level code execution. Any organization running an internet-exposed Sentry instance that has not yet patched should treat this as a presumed-compromise event. Ivanti products have been consistent targets for nation-state actors; isolate the appliance, revoke associated certificates and service credentials, and conduct log analysis before reintroducing the device into production. CISA's BOD 26-04 forensic triage requirements apply here — passive patching alone is insufficient.

CVE-2026-35273 (Oracle PeopleSoft Enterprise PeopleTools) carried a June 15 deadline. Missing authentication on a critical function allowing full system takeover is as severe as it gets for an ERP platform. PeopleSoft environments frequently hold HR, payroll, and identity data. If your PeopleSoft environment is internet-routable — even partially — assume the authentication bypass has been probed and verify access logs against known scanner and exploitation signatures. Apply Oracle's CPU patch immediately; if patching is not operationally feasible, restrict access to trusted network segments and enforce MFA at the network perimeter as a compensating control.

CVE-2026-54420 (LiteSpeed cPanel Plugin) had a June 18 deadline — yesterday. This symlink-following vulnerability targets shared hosting infrastructure running CloudLinux/CageFS and is exploitable by any user with FTP or web shell access. The risk here is lateral movement across hosting tenants. Managed hosting providers and web operations teams running LiteSpeed in multi-tenant environments should audit FTP account permissions and verify CageFS integrity in addition to patching. This class of vulnerability is commonly chained with low-privilege initial access from credential stuffing.

CVE-2026-48907 (Widget Factory Joomla Content Editor) had a June 19 deadline — today. Improper access control allows unauthenticated users to create editor profiles and upload and execute arbitrary PHP code. This is effectively an unauthenticated webshell-deployment primitive on any Joomla site running the affected plugin. If patching is not already in progress, disable the plugin now. Identify all systems where this plugin is active and treat any unrecognized PHP files in upload or editor directories as indicators of compromise.

Infrastructure Management Planes Under Active Threat — Cisco SD-WAN and Splunk

Two Cisco and one Splunk entry this cycle converge on a dangerous pattern: exploitation of network and security management infrastructure where successful attacks grant attackers control over the tools defenders rely on.

CVE-2026-20262 and CVE-2026-20245 both affect Cisco Catalyst SD-WAN Manager, with a shared patch deadline of June 23. The path traversal flaw (CVE-2026-20262) allows an authenticated remote attacker to create or overwrite arbitrary files on the filesystem — a capability frequently used to stage persistence or corrupt configurations. The output escaping flaw (CVE-2026-20245) allows an authenticated local attacker to execute arbitrary commands as root via a crafted file. Together, these represent a two-stage escalation risk: lateral movement or credential theft provides authentication, then CVE-2026-20262 enables filesystem manipulation, and CVE-2026-20245 completes the privilege escalation chain. Cisco has published advisories; apply the unified SD-WAN Manager patch bundle before the June 23 deadline and audit SD-WAN Manager access logs for unexpected authenticated sessions, particularly from VPN or jump-host infrastructure.

CVE-2026-20253 (Splunk Enterprise) has an aggressive deadline of June 21 — this Sunday. The missing authentication vulnerability exposes a PostgreSQL sidecar service endpoint to unauthenticated file creation and truncation. In practice, this means an attacker without any credentials can destroy log data, overwrite configuration files, or plant malicious content in file paths Splunk will later process. For organizations using Splunk as a SIEM or compliance logging platform, this is a defense evasion and data integrity threat as much as a direct compromise vector. BOD 26-04 requirements are explicitly cited in CISA's entry. Prioritize isolation of the Splunk management port from internet exposure immediately, then patch before Sunday's deadline. Verify log integrity for any Splunk instance that may have been exposed.

Browser Engine Exposure — Chromium V8 Requires Broad Sweep

CVE-2026-11645 (Google Chromium V8) carries a June 23 deadline and affects every Chromium-based browser including Google Chrome, Microsoft Edge, and Opera. The out-of-bounds read/write vulnerability enables arbitrary code execution within the sandbox via a crafted HTML page. While sandbox escapes typically require chaining, this primitive is valuable to threat actors targeting analyst workstations, developer endpoints, and any environment where users browse untrusted content. Patch deployment here must be treated as fleet-wide, not just BYOD or unmanaged endpoints. Verify that enterprise browser update policies are enforcing version compliance and that any Chromium-embedded applications in your software stack — Electron apps, kiosk browsers, internal tooling — are also updated. Do not rely solely on auto-update for managed fleets.

Summary Deadline Table

| CVE | Product | Deadline | Status | |---|---|---|---| | CVE-2026-10520 | Ivanti Sentry | Jun 14 | Overdue | | CVE-2026-35273 | Oracle PeopleSoft | Jun 15 | Overdue | | CVE-2026-48907 | Joomla Content Editor | Jun 19 | Due Today | | CVE-2026-54420 | LiteSpeed cPanel Plugin | Jun 18 | Overdue | | CVE-2026-20253 | Splunk Enterprise | Jun 21 | 2 days | | CVE-2026-11645 | Chromium V8 | Jun 23 | 4 days | | CVE-2026-20262 | Cisco SD-WAN Manager | Jun 29 | 10 days | | CVE-2026-20245 | Cisco SD-WAN Manager | Jun 23 | 4 days |

Sources: CISA KEV Catalog · CISA BOD 26-04 · Cisco Security Advisories · Ivanti Security Advisories · Oracle Critical Patch Update · Splunk Security Advisories · Google Chrome Releases · CISA Alert on Ivanti Exploits

Free KEV Alerts

  • Real-time notification the moment a KEV drops
  • Vendor and product details
  • BOD 26-04 remediation deadline included

Pro Alerts Coming Soon

  • Real-time notification the moment a KEV drops
  • Filtered to your specific vendor watchlist
  • Urgency scoring (Critical / Urgent / Standard)
  • Direct patch links included

Stay ahead of CISA.

No spam. Unsubscribe anytime. We don't sell your data.


Upcoming Patch Due Dates

via Binding Operational Directive 26-04

BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.

Loading...

News Logo

Cyber Security News

You may have missed...


📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://www.wsj.comJun 18

How Hackers Found a Back Door Into the American Living Room

Nation-state cyberattackers are increasingly using residential proxy networks to mask their traffic, turning everyday electronics into a global threat

https://www.pv-magazine.comJun 16

The real cybersecurity debate around chinese inverters is only just beginning - PV Magazine

The European Commission's move to restrict funding for projects using high-risk inverter vendors marks a turning point for solar cybersecurity.

https://www.silicon.co.ukJun 16

China-Linked Hackers Stole Data For More Than A Year - Silicon UK

The hackers sought materials related to defence intelligence, military strategy in the Indo-Pacific region, AI, unmanned vehicles, cyber warfare ...

https://thehackernews.comJun 16

China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth

Cybersecurity researchers have flagged two previously undocumented Windows variants of what was believed to be a Linux-only backdoor called SprySOCKS.

https://www.northcountrypublicradio.orgJun 17

Can computer hackers get inside your mind? | NCPR News

On today's show: a whodunit about hackers, 'Cyber Paleontologists', spy-vs-spy protocols, cryptic intelligence leaks, nuclear physics, high-precision ...

https://www.wired.comJun 17

'Dangerous' AI Models Are Coming No Matter What | WIRED

The US government crackdown on Anthropic's Claude Fable 5 and Mythos 5 hides a glaring truth: AI models with advanced hacking capabilities will ...

https://www.axios.comJun 16

Trump's Anthropic crackdown rattles cyber defenders - Axios

AI researchers and cybersecurity leaders fear the U.S. government is setting a precedent that may discourage American AI companies from building ...

https://thehackernews.comJun 17

CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting Widget Factory Joomla ...


Updated daily