This month: 19 KEVs detected

CISA stopped reliably sending KEV alerts.
We didn't.

CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.

CVE-2026-8398
Daemon · Daemon Tools Lite
Daemon Tools Lite Embedded Malicious Code Vulnerability
Detected May 27 · 3-day patch deadline
CVE-2026-48172
LiteSpeed · cPanel Plugin
LiteSpeed cPanel Plugin Privilege Escalation Vulnerability
Detected May 26 · 3-day patch deadline
CVE-2026-20182
Cisco · Catalyst SD-WAN
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
Detected May 14 · 3-day patch deadline

Developer Toolchain Under Siege: A Supply Chain Triple-Threat

Three of the six most recent additions to CISA's Known Exploited Vulnerabilities catalog share a common and deeply unsettling trait: the attack surface wasn't a misconfigured server or an unpatched library — it was the developer's own trusted toolchain. CVE-2026-48027 (Nx Console), CVE-2026-45321 (TanStack), and CVE-2026-8398 (Daemon Tools Lite) all involve malicious code embedded or published under trusted identities, then distributed through automatic update mechanisms to developers who did nothing wrong. The Nx Console compromise is particularly notable given CISA's simultaneous advisory on the broader "Megalodon" GitHub CI/CD campaign — these aren't isolated incidents, they're coordinated pressure on the same ecosystem layer.

The pattern here is deliberate targeting of developer trust infrastructure. By poisoning npm packages and VS Code extensions — tools that live inside the development environment itself — threat actors gain access not just to production systems, but to the credentials, tokens, and secrets that build those systems. A compromised CI/CD pipeline is a master key. Federal contractors and any organization operating cloud or DevOps environments should treat credential rotation not as a remediation step but as an immediate operational priority, particularly for any pipeline secrets, API keys, or cloud provider credentials that may have touched an affected environment since mid-May.

Deadline Watch: LiteSpeed, Drupal, and the Compliance Clock

Two other KEVs demand attention based on deadline urgency alone. CVE-2026-48172 in the LiteSpeed cPanel Plugin — a privilege escalation that hands root-level access to any authenticated user — had its patch deadline pass this week, meaning organizations still running vulnerable versions are operating outside federal compliance windows. CVE-2026-9082 in Drupal Core is a SQL injection in the database abstraction layer, enabling both data theft and remote code execution; its deadline has also elapsed. Shared hosting providers and organizations running government-facing Drupal installations should assume active exploitation is underway.

The Zombie in the Room: Internet Explorer, 2010

Finally: CVE-2010-0249. Yes, 2010. Internet Explorer's use-after-free vulnerability made the KEV catalog this week as a reminder that "deprecated" and "safe" are not synonyms. If any system in your environment still touches IE — embedded in kiosks, legacy intranet apps, or aging Windows builds — there is no patch coming. The only remediation is elimination. The fact that CISA still finds this worth cataloging in 2026 tells you everything about the persistence of legacy attack surface in enterprise environments.

Sources: CISA KEV Catalog · CISA Advisory: Nx Console / Megalodon · GitHub Security Advisory GHSA-c9j4-9m59-847w · Ox Security: Megalodon · StepSecurity: Nx Console Compromise

Free KEV Alerts

  • Real-time notification the moment a KEV drops
  • Vendor and product details
  • BOD 22-01 deadline included

Pro Alerts Coming Soon

  • Real-time notification the moment a KEV drops
  • Filtered to your specific vendor watchlist
  • Urgency scoring (Critical / Urgent / Standard)
  • Direct patch links included

Stay ahead of CISA.

No spam. Unsubscribe anytime. We don't sell your data.


Upcoming Patch Due Dates

via Binding Operational Directive 22-01

(BOD) 22-01 is a directive issued by the Cybersecurity and Infrastructure Security Agency (CISA) in the United States to federal agencies and federal contractors in order to improve their cybersecurity practices. It provides a set of guidelines and requirements that these agencies and contractors must follow to increase their defenses against cyber threats.

Loading...

News Logo

Cyber Security News

You may have missed...


📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://blog.barracuda.comMay 29

Nightmare-Eclipse: Six Zero-Days, Six Weeks and One Big Grudge

A rogue security researcher known as Nightmare-Eclipse has released six unpatched Windows zero-day exploits (BlueHammer, RedSun, UnDefend, YellowKey, ...

https://ca.finance.yahoo.comMay 29

Scammers are using a fake captcha hack to steal your information - Yahoo! Finance Canada

Hackers are using this insidious scam to get unwitting victims to install malware themselves.

https://www.bankinfosecurity.comMay 29

Connecticut Medicaid Portal Hack Affects Thousands - BankInfoSecurity

A hack on a Connecticut Medicaid web portal involving compromised credentials of a healthcare provider has affected the payment account and other ...

https://www.cbsnews.comMay 29

Colorado cybersecurity office announces mass layoffs following scathing audits - CBS News

The Colorado office responsible for overseeing the state's cybersecurity and digital infrastructure announced sweeping layoffs and a major ...

https://www.pcmag.comMay 29

Microsoft Threatens Researcher Over Bug Reports, Triggers Cybersecurity Uproar | PCMag

The cybersecurity community is blasting Microsoft for threatening legal action against a disgruntled researcher who's been exposing Windows ...

https://thefinancialbrand.comMay 29

Digital Growth Is Outpacing Cybersecurity at Credit Unions - The Financial Brand

But this growth comes with a cost that many credit union leaders are only beginning to fully appreciate—the cybersecurity frameworks they have in ...

https://thehackernews.comMay 29

Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer

The issue was addressed by Fortinet in FortiClient EMS 7.4.7 and later. Cybersecurity. A successful compromise is followed by the threat actor taking ...

https://fox59.comMay 28

What is a wrench attack, and why are cryptocurrency robberies on the rise globally? - Fox 59

He also pointed to improvements in digital security that make it so criminals “have no option but to basically hold you at gunpoint and say, 'Enter .....


Updated daily