This month: 24 KEVs detected

CISA stopped reliably sending KEV alerts.
We didn't.

CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.

CVE-2026-48558
SimpleHelp · SimpleHelp
SimpleHelp Authentication Bypass Vulnerability
Detected Jun 29 · 3-day patch deadline
CVE-2026-12569
PTC · Windchill and FlexPLM
PTC Windchill and FlexPLM Improper Input Validation Vulnerability
Detected Jun 25 · 3-day patch deadline
CVE-2026-20230
Cisco · Unified Communications Manager
Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability
Detected Jun 25 · 3-day patch deadline

KEV Intelligence Brief — June 29, 2026

Prepared for: Federal Contractors · DevOps & Platform Teams · Security Operations Leaders Issued: Monday, June 29, 2026 | Catalog Window: June 16–25, 2026

Eight vulnerabilities added to CISA's KEV catalog over the past two weeks span enterprise PLM platforms, unified communications infrastructure, networking gear, and web content management — with several patch deadlines already elapsed. All entries carry BOD 26-04 obligations. Federal agencies and their contractors are out of time on most of these; commercial operators should treat them with equivalent urgency given confirmed exploitation.

Overdue and Critical: Unauthenticated RCE Across Enterprise Infrastructure

The most technically severe cluster in this cycle involves vulnerabilities that require no authentication and enable direct code execution or privileged file manipulation — the conditions threat actors prize most.

CVE-2026-12569 (PTC Windchill and FlexPLM, deadline: June 28) represents the highest-stakes entry in this brief. Windchill is deeply embedded in defense and aerospace supply chains as a product lifecycle management backbone; FlexPLM serves retail and apparel manufacturing. An unauthenticated remote attacker can send a malicious network request to achieve arbitrary code execution — no credentials, no prior access required. If your organization runs Windchill or FlexPLM with any internet-facing exposure, that exposure should have been eliminated before the deadline passed yesterday. If patching is not yet complete, isolate affected systems at the network perimeter immediately, review ingress logs for anomalous POST traffic to API endpoints, and initiate vendor-guided forensic triage per BOD 26-04 requirements before reintroducing connectivity.

CVE-2026-20230 (Cisco Unified Communications Manager and Unified CM SME, deadline: June 28) is a server-side request forgery vulnerability that permits unauthenticated file writes to the underlying OS — a stepping stone to root escalation. Cisco Unified CM is pervasive in federal and enterprise telephony environments, and SSRF-to-file-write chains in this class of product have historically been leveraged for persistent backdoor installation. Administrators should apply Cisco's advisory patches immediately, audit recent file system changes in /tmp and application directories, rotate service account credentials, and verify that Unified CM management interfaces are not exposed directly to untrusted networks. Both CVE-2026-12569 and CVE-2026-20230 share the same June 28 deadline — as of today, both are overdue.

CVE-2026-20253 (Splunk Enterprise, deadline: June 21 — now eight days overdue) allows an unauthenticated user to create or truncate arbitrary files through an exposed PostgreSQL sidecar service endpoint. In a SIEM context, the implications extend beyond the Splunk platform itself: an attacker who can truncate log files or inject synthetic records can blind your detection capability and manipulate audit trails. Splunk Enterprise environments that have not yet patched should immediately restrict network access to the PostgreSQL sidecar port (typically 5432) to localhost or trusted management subnets only, then patch without delay. Forensic review of recent file activity around Splunk's data and configuration directories is warranted given the elapsed deadline.

Network Infrastructure Under Pressure: Ubiquiti UniFi and Lantronix EDS5000

A second cluster involves network infrastructure devices — the layer of the environment that defenders often patch last but attackers target first for lateral movement and persistent access.

Ubiquiti's UniFi OS received three simultaneous KEV entries (deadline: June 26, now three days overdue): CVE-2026-34908 (improper access control enabling unauthorized system changes), CVE-2026-34909 (path traversal enabling filesystem access and account compromise), and CVE-2026-34910 (improper input validation enabling command injection). These three vulnerabilities form a logical exploitation chain for any attacker already on a network segment hosting UniFi controllers or gateways — access control bypass opens the door, path traversal exposes credential material, and command injection delivers execution. UniFi hardware is common in enterprise branch offices, university campuses, and government facilities that have embraced prosumer-grade networking. All three require network access rather than internet exposure, which means a phishing-delivered implant or compromised endpoint already inside the perimeter is sufficient for exploitation. Patch UniFi OS immediately, audit active sessions and administrator accounts, and consider segmenting UniFi management traffic to a dedicated VLAN with strict ACLs.

CVE-2025-67038 (Lantronix EDS5000, deadline: June 26) is a code injection vulnerability in the device's username parameter that executes injected OS commands with root privileges. The EDS5000 is a serial-to-Ethernet device server found in industrial control and operational technology environments — precisely the environments where unpatched network-accessible devices tend to persist for years. OT/ICS operators should treat this with the same urgency as a PLC vulnerability. If vendor patches are unavailable or operationally infeasible, isolate EDS5000 devices behind a protocol-aware firewall, disable remote management interfaces where possible, and document compensating controls for BOD 26-04 reporting.

Web Platform Exposure: Joomla Content Editor

CVE-2026-48907 (Widget Factory Joomla Content Editor, deadline: June 19 — now ten days overdue) rounds out this cycle with an improper access control vulnerability enabling unauthenticated users to create new editor profiles and upload and execute arbitrary PHP code. This is effectively an unauthenticated webshell deployment path against any Joomla site running the affected plugin. Web content management vulnerabilities of this class are routinely mass-exploited within days of KEV listing. Security teams managing Joomla deployments should verify patch status, scan the web root for recently created or modified PHP files outside of known-good paths, review web server access logs for suspicious POST requests targeting editor profile creation endpoints, and rotate any credentials stored in or accessible from the CMS database.

Sources: CISA KEV Catalog · CISA BOD 26-04 · Cisco Security Advisory — Unified CM SSRF · PTC Security Advisories · Splunk Security Advisories · Ubiquiti Security Advisories · Lantronix Product Security · CISA ICS Advisories

Free KEV Alerts

  • Real-time notification the moment a KEV drops
  • Vendor and product details
  • BOD 26-04 remediation deadline included

Pro Alerts Coming Soon

  • Real-time notification the moment a KEV drops
  • Filtered to your specific vendor watchlist
  • Urgency scoring (Critical / Urgent / Standard)
  • Direct patch links included

Stay ahead of CISA.

No spam. Unsubscribe anytime. We don't sell your data.


Upcoming Patch Due Dates

via Binding Operational Directive 26-04

BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.

Loading...

News Logo

Cyber Security News

You may have missed...


📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://www.helpnetsecurity.comJun 5

Cisco Catalyst SD-WAN Manager Zero-Day Privilege Escalation Being Exploited (CVE-2026-20245)

An unpatched zero-day privilege escalation vulnerability in Cisco Catalyst SD-WAN Manager is being actively exploited by attackers in the wild.

https://thehackernews.comJun 29

Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw

It never enforced an upper bound. Cybersecurity. The size calculation adds packet_length to a couple of small values using 32-bit arithmetic, so a ...

https://www.justice.govJun 27

Former U.S. National Security Advisor John R. Bolton, II Pleads Guilty to Violating the Espionage Act

... hacked by a cyber actor allegedly linked to the Islamic Republic of Iran. ... Bolton reported that hack to law enforcement but did not tell the .....

https://thehill.comJun 27

Secret Service didn't secure mobile devices, putting leaders at risk, report says - The Hill

Secret Service agents' reliance on personal devices for official business exposes them to hacking risks, says government watchdog report.

https://www.bankinfosecurity.comJun 27

A Hack Too Far? Report Ties Russia to Jaguar Land Rover Hit - BankInfoSecurity

Suggestions that the Kremlin orchestrated the disruptive hack attack against British automotive giant Jaguar Land Rover raise the question of how ...

https://www.nytimes.comJun 26

A $2.5 Billion Whodunit: The Hack That Dented the U.K. Economy - The New York Times

Last year, hackers burrowed into the computer systems of Jaguar Land Rover, a crown jewel of British manufacturing. It was a devastating attack ...

https://abcnews.comJun 26

Iranian national sought by US on hacking charges arrested in Montenegro - ABC News

Montenegrin police say they have arrested an Iranian national who is wanted by the United States for mass hacking attacks that caused damage of ...

https://thehackernews.comJun 26

Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack

Cybersecurity researchers have flagged yet another evolution of the supply chain attack linked to the Mini Shai-Hulud, Miasma, and Hades malware ...


Updated daily