This month: 6 KEVs detected

CISA stopped reliably sending KEV alerts.
We didn't.

CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.

CVE-2026-45247
Mirasvit · Mirasvit Full Page Cache Warmer
Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability
Detected Jun 3 · 3-day patch deadline
CVE-2022-0492
Linux · Kernel
Linux Kernel Improper Authentication Vulnerability
Detected Jun 2 · 3-day patch deadline
CVE-2025-48595
Android · Framework
Android Framework Integer Overflow Vulnerability
Detected Jun 2 · 3-day patch deadline

Developer Toolchain Under Siege: A Supply Chain Triple-Threat

Three of the six most recent additions to CISA's Known Exploited Vulnerabilities catalog share a common and deeply unsettling trait: the attack surface wasn't a misconfigured server or an unpatched library — it was the developer's own trusted toolchain. CVE-2026-48027 (Nx Console), CVE-2026-45321 (TanStack), and CVE-2026-8398 (Daemon Tools Lite) all involve malicious code embedded or published under trusted identities, then distributed through automatic update mechanisms to developers who did nothing wrong. The Nx Console compromise is particularly notable given CISA's simultaneous advisory on the broader "Megalodon" GitHub CI/CD campaign — these aren't isolated incidents, they're coordinated pressure on the same ecosystem layer.

The pattern here is deliberate targeting of developer trust infrastructure. By poisoning npm packages and VS Code extensions — tools that live inside the development environment itself — threat actors gain access not just to production systems, but to the credentials, tokens, and secrets that build those systems. A compromised CI/CD pipeline is a master key. Federal contractors and any organization operating cloud or DevOps environments should treat credential rotation not as a remediation step but as an immediate operational priority. That urgency compounds with CVE-2022-0492 in the Linux Kernel, also due Friday: a privilege escalation via the cgroups v1 release_agent feature that allows a low-level user to gain full control of a host. In containerized environments — which overlap heavily with the CI/CD environments targeted by the supply chain attacks above — this vulnerability represents a container escape risk. Patch both, patch them together.

Deadline Watch: PAN-OS, WebLogic, and Android on the Clock

Three KEVs demand immediate attention this cycle, all with deadlines inside 72 hours. CVE-2026-0257 in Palo Alto Networks PAN-OS is an authentication bypass that allows attackers to establish unauthorized VPN connections — no credentials required. Palo Alto firewalls and VPN concentrators are perimeter infrastructure, meaning a successful exploit doesn't just compromise one system, it compromises the boundary between your network and everything outside it. CVE-2024-21182 in Oracle WebLogic Server follows the same pattern at the application layer: unauthenticated attackers with network access via T3 or IIOP can compromise the server entirely. Any environment running WebLogic with external network access should be treated as a priority patch target before Thursday.

CVE-2025-48595 in the Android Framework rounds out the deadline pressure with a different threat surface entirely. An integer overflow in Android's core framework allows malicious apps to escalate privileges and execute arbitrary code — meaning a single compromised app can own the device. With a Friday deadline, this one applies to every Android device in your organization, not just servers. Mobile device management policies that defer OS updates should be temporarily suspended for this cycle.

Sources: CISA KEV Catalog · CISA Advisory: Nx Console / Megalodon · GitHub Security Advisory GHSA-c9j4-9m59-847w · Ox Security: Megalodon · StepSecurity: Nx Console Compromise

Free KEV Alerts

  • Real-time notification the moment a KEV drops
  • Vendor and product details
  • BOD 22-01 deadline included

Pro Alerts Coming Soon

  • Real-time notification the moment a KEV drops
  • Filtered to your specific vendor watchlist
  • Urgency scoring (Critical / Urgent / Standard)
  • Direct patch links included

Stay ahead of CISA.

No spam. Unsubscribe anytime. We don't sell your data.


Upcoming Patch Due Dates

via Binding Operational Directive 22-01

(BOD) 22-01 is a directive issued by the Cybersecurity and Infrastructure Security Agency (CISA) in the United States to federal agencies and federal contractors in order to improve their cybersecurity practices. It provides a set of guidelines and requirements that these agencies and contractors must follow to increase their defenses against cyber threats.

Loading...

News Logo

Cyber Security News

You may have missed...


📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://thehackernews.comJun 5

Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories

Because those permissions are broad, the action is supposed to be picky about who can trigger it: only users with write access. Cybersecurity. The ...

https://www.theregister.comJun 5

Visual Studio Code Zero-Click Exploit Allows GitHub Token Theft

A security researcher disclosed a proof-of-concept exploit for VS Code that allows attackers to steal GitHub tokens with full repository access by cli...

https://hackaday.comJun 5

If You Want To Hack Me, Come In Through The Speaker | Hackaday

Some security hacks require someone to have physical access to your computer. In many cases, that's easy to mitigate. Other attack vectors can put ...

https://www.govinfosecurity.comJun 4

Cryptohack Roundup: US Strikes Iran's Crypto Network - GovInfoSecurity

Blockchain security firms reported the attacker minted more than 5.4 trillion vote-boosted vsdCRV tokens on the arbitrum network. Security researchers...

https://www.coindesk.comJun 4

Live updates: Bitcoin bounces, HYPE falls, NEAR gets demolished as crypto deals with a wipe out

"Their launch of preferred stock has put a 4%+ annual dilution burden on common stockholders and cost MSTR the most out of any security. Not only that...

https://www.youtube.comJun 4

Crypto Security: Hot vs Cold Wallets Explained! #shorts - YouTube

Never keep all your crypto in a hot wallet! Learn why 80-90% should be in a cold wallet (like Ledger or Trezor) for maximum security.

https://unit42.paloaltonetworks.comMar 13

Suspected China-Based Espionage Operation Against Military Targets in Southeast Asia

Palo Alto Networks Unit 42 identified a suspected China-based espionage campaign targeting military organizations across Southeast Asia with custom ba...

https://thehackernews.comJun 5

PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network

... hacking group that has attracted attention in recent months for its ... © 2026 The Hacker News. All Rights Reserved.


Updated daily