CISA stopped reliably sending KEV alerts.
We didn't.
CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.
KEV Intelligence Brief — June 25, 2026
Issued: Thursday, June 25, 2026 | Audience: Federal Contractors, DevOps, SOC Leadership | Authority: CISA BOD 26-04
Immediate Action Required: Unauthenticated RCE and File Manipulation at Scale
The most operationally severe entries in this week's KEV additions share a common and dangerous profile: unauthenticated remote attackers with a direct path to code execution or persistent file manipulation. Federal agencies and contractors operating under BOD 26-04 should treat these as P1 remediation events.
CVE-2026-12569 targets PTC Windchill and FlexPLM, two platforms deeply embedded in defense industrial base (DIB) and manufacturing supply chains. The improper input validation flaw requires no authentication and enables arbitrary code execution via a single malicious network request. Given Windchill's role in managing product lifecycle data—often including controlled unclassified information (CUI) and technical data packages—exploitation could have cascading downstream consequences well beyond the host system. The patch deadline is June 28, leaving a three-day window. Organizations that cannot immediately patch should isolate Windchill and FlexPLM instances from internet-facing segments, enforce network-layer access controls, and initiate forensic triage in accordance with CISA's Forensics Triage Requirements before applying the patch to preserve evidence of potential pre-patch compromise.
CVE-2026-20230 affects Cisco Unified Communications Manager and its Session Management Edition (Unified CM SME). The SSRF vulnerability allows an unauthenticated attacker to write arbitrary files to the underlying OS—a classic staging mechanism for privilege escalation to root. The attack chain here is particularly concerning: SSRF-to-file-write-to-root is a well-understood lateral progression that threat actors automate rapidly once a PoC surfaces. Unified CM is widely deployed across federal and enterprise telephony infrastructure. The patch deadline is also June 28. If patching cannot be completed in time, restrict external access to the Unified CM web interface at the perimeter, audit recent file system changes, and rotate any service account credentials with local access to the platform.
CVE-2026-20253 in Splunk Enterprise presents a similar unauthenticated file creation and truncation primitive via an exposed PostgreSQL sidecar service endpoint. Its patch deadline of June 21 has already passed, meaning any organization still running the vulnerable version is in active BOD 26-04 noncompliance. Beyond the compliance posture, file truncation capabilities against a SIEM platform carry a secondary risk: adversaries could weaponize this to corrupt log pipelines and degrade detection visibility before executing broader intrusion activity. Verify patching status immediately, review PostgreSQL sidecar service exposure, and conduct log integrity checks for anomalous truncation events dating back to mid-June.
Network Infrastructure Under Coordinated Pressure: The Ubiquiti UniFi Cluster
Three CVEs added on June 23 target Ubiquiti UniFi OS, and their simultaneous KEV inclusion signals active exploitation of this platform as a combined attack surface rather than isolated incidents.
CVE-2026-34908 (improper access control), CVE-2026-34909 (path traversal), and CVE-2026-34910 (improper input validation enabling command injection) each require only local network access—not public internet exposure—to exploit. That framing should not breed complacency. In segmented enterprise environments, any foothold inside the network perimeter, including a compromised endpoint or a guest VLAN with insufficient isolation, could provide the necessary access. The path traversal in CVE-2026-34909 is particularly notable: file access enabling account compromise creates a persistence mechanism that survives a reboot or firmware flash if attacker-controlled accounts are established at the OS level.
The June 26 patch deadline has effectively arrived. Organizations running UniFi OS controllers should apply the vendor update immediately, audit for unauthorized administrative accounts, rotate all UniFi console credentials, and verify that management interfaces are bound only to dedicated management VLANs with strict ACL enforcement. For organizations that cannot patch within the window, disabling remote management features and isolating the controller from general-purpose network segments is the minimum acceptable interim posture.
Web-Facing Targets: CMS Exploitation and Industrial Serial Servers
Two remaining entries represent distinct but equally exploitable web-facing attack surfaces with overdue patch deadlines.
CVE-2026-48907 in Widget Factory's Joomla Content Editor has a patch deadline of June 19—now six days overdue. The improper access control flaw allows unauthenticated users to create new editor profiles and upload and execute arbitrary PHP code, effectively delivering a webshell primitive to any attacker who can reach the Joomla instance. Any organization hosting public-facing Joomla sites with this plugin installed should assume compromise if the patch has not been applied, conduct a full review of recently created editor profiles and uploaded files, and consider taking the affected site offline for forensic review before restoration.
CVE-2025-67038 in the Lantronix EDS5000—an industrial Ethernet device server used to network-enable legacy serial devices—allows OS command injection via the username parameter, with injected commands executing as root. Its patch deadline is June 26. The EDS5000 is frequently deployed in OT/ICS environments where patching cycles are constrained by operational continuity requirements. If an immediate patch is operationally infeasible, segment the device behind an OT DMZ, disable web-based management interfaces accessible from IT networks, and monitor for anomalous outbound connections indicative of command-and-control activity.
Analyst Notes
Across all eight entries, the recurring pattern is authentication bypass or absence as the primary attack enabler. Five of eight vulnerabilities require no valid credentials for initial exploitation. This is not coincidence—it reflects sustained adversary interest in eliminating the credential barrier entirely. SOC teams should prioritize unauthenticated inbound traffic analysis against the affected products and treat any unexpected sessions against these services as potentially malicious pending investigation.
Sources: CISA KEV Catalog · CISA BOD 26-04 · Cisco Security Advisories · PTC Security Advisories · Splunk Security Advisories · Ubiquiti Security Advisories · Lantronix Support Portal · CISA ICS Advisories
Free KEV Alerts
- Real-time notification the moment a KEV drops
- Vendor and product details
- BOD 26-04 remediation deadline included
Pro Alerts Coming Soon
- Real-time notification the moment a KEV drops
- Filtered to your specific vendor watchlist
- Urgency scoring (Critical / Urgent / Standard)
- Direct patch links included
Stay ahead of CISA.
Common Vulnerability and Exposure
CVEs form a database of known security vulnerabilities that are actively tracked and managed by a group of organizations, such as the U.S. National Cyber Security Alliance. CVEs are an important tool for network security management because they not only provide an inventory of existing vulnerabilities, but also provide information about how the vulnerability can be exploited and instructions on how to protect against it.
Search the KEV Catalog by Vendor or Product
Search for CVEs by vendor or product to identify known exploited vulnerabilities in your environment
Upcoming Patch Due Dates
via Binding Operational Directive 26-04
BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.
Loading...
Cyber Security News
You may have missed...
*
Inside a cyberattack: How hackers steal data
The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...
87% of cybersecurity managers say quick compliance programs are actually increasing risk ...
Speed-focused compliance programs could help businesses get cybersecurity certifications quicker, but security professionals are skeptical if the ...
Cybersecurity agencies flags use of covert networks by China-linked actors for espionage, offensive operations
NCSC-UK and international cybersecurity agencies warned that China-nexus threat actors are building and maintaining hidden networks of hijacked device...
FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation
... Hacker News. "The same pairs also appear in the actor's input target list EU.txt (the file their Go scanner reloads and re-validates every cycle ....
Five Eyes cybersecurity agencies warn of new AI models impact on cyber risks - CBC
Cutting-edge artificial intelligence technology is poised to supercharge offensive hacking ... Hacking concerns. The Monday statement from the Five ....
White House PQC order 'lights a fire' under post-quantum transition | Federal News Network
Cybersecurity experts are particularly concerned that U.S. adversaries could steal data today and decrypt using a quantum computer in the future ...
N.S.A. Lost Access to Powerful A.I. Model Amid Anthropic Dispute - The New York Times
A recent episode underscored the Trump administration's increasing reliance on advanced A.I. systems for cybersecurity even as it battles a ...
Dragos launches EmberAI to bring OT-native AI to industrial cybersecurity operations
Threat activity against critical infrastructure is accelerating. The OT cybersecurity skills needed to address these complex tactics and techniques .....
How 100 Romanian hospitals switched to pen and paper to defeat a national cyber-attack
Around the same time, Change Healthcare in the US was hacked, leading to widespread disruption. The company paid a $22m (£16m) ransom to hackers.
Updated daily
