This month: 13 KEVs detected

CISA stopped reliably sending KEV alerts.
We didn't.

CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.

CVE-2026-35273
Oracle · PeopleSoft Enterprise PeopleTools
Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability
Detected Jun 12 · 3-day patch deadline
CVE-2026-10520
Ivanti · Sentry
Ivanti Sentry OS Command Injection Vulnerability
Detected Jun 11 · 3-day patch deadline
CVE-2026-50751
Check Point · Security Gateway
Check Point Security Gateway Improper Authentication Vulnerability
Detected Jun 8 · 3-day patch deadline

KEV Intelligence Brief: June 12, 2026

Issued: Friday, June 12, 2026 | Audience: Federal Contractors, DevOps, Security Operations

Eight new entries landed in CISA's Known Exploited Vulnerabilities (KEV) catalog this week, spanning network security gateways, enterprise mobility infrastructure, AI tooling, browser engines, and enterprise applications. One deadline has already passed, with several more arriving over the next eleven days. The pattern is unmistakable: attackers are systematically targeting authentication bypass and command injection primitives across the stack, from the network edge inward to developer and AI platforms.

Deadline Watch: Authentication Bypasses at the Network Edge

The most operationally urgent entries this week are CVE-2026-50751 in Check Point Security Gateway and CVE-2026-35273 in Oracle PeopleSoft Enterprise PeopleTools. One deadline has already passed, and the other arrives Monday.

The Check Point vulnerability (patch deadline: June 11—already passed) is particularly alarming. The flaw affects VPN deployments configured to use the deprecated IKEv1 key exchange protocol, allowing an unauthenticated remote attacker to bypass authentication controls and establish a VPN tunnel without a valid password. This is not a privilege escalation issue; it is a front-door bypass. Any organization running Check Point Security Gateway with internet-exposed IPsec remote access VPN services should treat this as an active incident until patched. Immediate steps beyond patching include reviewing VPN session logs for anomalous IKEv1 connection attempts, rotating credentials for accounts whose sessions may have been established through this pathway, and considering temporary disablement of IKEv1 in favor of IKEv2 if remediation cannot be completed immediately.

CVE-2026-35273 in Oracle PeopleSoft PeopleTools carries a deadline of June 15—three days from today and squarely within BOD 26-04's accelerated patching window. The missing authentication condition enables remote compromise without any prior access, making internet-exposed PeopleSoft instances immediate targets. Federal contractors running PeopleSoft for HR, payroll, or procurement workflows should prioritize this above nearly everything else on their patch queue this week. If patching cannot be completed by Monday, isolate the application tier from public-facing networks and enforce network-layer access controls until remediation is complete.

Unauthenticated RCE, Privileged Command Execution, and Availability Risk: Ivanti, SolarWinds, and Cisco

Three entries this week target the platforms organizations rely on to manage users, infrastructure, and critical workflows. Together, they demonstrate why management systems remain among the highest-value targets in enterprise environments.

Ivanti Sentry (CVE-2026-10520, deadline: June 14) continues a troubling pattern for a product line that has repeatedly attracted attacker attention. This OS command injection vulnerability allows a remote unauthenticated attacker to achieve root-level remote code execution. CISA's BOD 26-04 forensic triage requirements apply explicitly here. Do not patch and move on. Treat any unpatched Sentry instance as potentially compromised and conduct artifact collection before applying fixes. Review MDM policy push logs, administrative activity, and certificate stores for signs of persistence or lateral movement.

SolarWinds Serv-U (CVE-2026-28318, deadline: June 19) presents a different but still serious risk profile. An unauthenticated attacker can crash the Serv-U service using a malformed Content-Encoding: deflate POST request, resulting in denial of service through uncontrolled resource consumption. In environments where Serv-U facilitates regulated file transfers—HIPAA, ITAR, or FedRAMP workloads—availability loss constitutes a compliance and business continuity concern rather than merely an operational nuisance. SolarWinds remains under heightened scrutiny following prior supply chain incidents, and any evidence of exploitation activity should trigger a broader investigation beyond the immediate service disruption.

Cisco Catalyst SD-WAN Manager (CVE-2026-20245, deadline: June 23) requires authenticated local access, which moderates—but does not eliminate—the potential impact. In SD-WAN environments, "local" frequently means anyone with administrative or CLI access to a management node. Arbitrary root command execution via a crafted file means a compromised operator credential can rapidly become a full infrastructure takeover vector. Organizations should review SD-WAN Manager access logs, enforce least privilege for management accounts, preserve forensic evidence where compromise is suspected, and apply vendor guidance or updates as they become available.

Developer and AI Toolchain Exposure: Chromium, Arista EOS, and LiteLLM

The remaining entries illustrate how the attack surface continues expanding into modern development workflows, browser environments, and AI infrastructure.

Google Chromium V8 (CVE-2026-11645, deadline: June 23) carries cross-browser implications because V8 underpins Chrome, Microsoft Edge, Opera, and other Chromium-based clients. The vulnerability involves out-of-bounds memory access triggered through a crafted HTML page, enabling arbitrary code execution within the browser's sandbox. Although not itself a sandbox escape, browser compromise remains a powerful initial access vector, particularly in environments where developers and analysts interact with sensitive internal applications through web interfaces. Apply browser updates promptly and avoid relying solely on slower enterprise deployment cycles.

Arista EOS (CVE-2026-7473, deadline: June 23) exposes a subtle but potentially dangerous forwarding flaw. Affected switches may incorrectly decapsulate and forward unexpected tunneled packets destined for configured decapsulation IP addresses. In high-security environments, unexpected forwarding behavior can undermine segmentation assumptions and trust boundaries. Organizations should review tunnel interface configurations, implement vendor-recommended mitigations, and reassess reliance on topology-based access controls until vulnerable configurations are remediated.

Finally, BerriAI LiteLLM (CVE-2026-42271, deadline: June 22) highlights a newer category of operational risk that many security teams are still learning to model. The command injection vulnerability is exploitable by any authenticated user, including low-privilege internal users with valid API credentials. Because LiteLLM is frequently deployed as a proxy layer for internal AI tooling, the threat model extends beyond external adversaries to include compromised developer accounts and exposed API keys. Rotate LiteLLM credentials, audit internal-user access, and evaluate whether host-level sandboxing or container isolation can reduce blast radius until remediation is complete.

Sources: CISA KEV Catalog · CISA BOD 26-04 · Oracle Security Alerts · Ivanti Security Advisory (Sentry) · Cisco Security Advisories · Check Point Security Advisory · SolarWinds Serv-U Advisory · Google Chrome Releases · Arista Security Advisories · BerriAI LiteLLM Security Advisories

Free KEV Alerts

  • Real-time notification the moment a KEV drops
  • Vendor and product details
  • BOD 26-04 remediation deadline included

Pro Alerts Coming Soon

  • Real-time notification the moment a KEV drops
  • Filtered to your specific vendor watchlist
  • Urgency scoring (Critical / Urgent / Standard)
  • Direct patch links included

Stay ahead of CISA.

No spam. Unsubscribe anytime. We don't sell your data.


Upcoming Patch Due Dates

via Binding Operational Directive 26-04

BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.

Loading...

News Logo

Cyber Security News

You may have missed...


📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://thehackernews.comJun 12

The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm

... cybersecurity company said. "Additionally, LARVA-368 relies heavily on ... The individual's identity has since been outed by cybersecurity ...

https://krebsonsecurity.comJun 9

Pro-Iran Hackers Exploit Meta AI to Hijack High-Value Instagram Accounts

Pro-Iran hackers released videos demonstrating how to exploit Meta's AI support chatbot to reset passwords on Instagram accounts without multi-factor ...

https://www.thezdi.comJun 9

Microsoft June 2026 Patch Tuesday: Record 208 CVEs with Multiple Zero-Days

Microsoft released its largest Patch Tuesday ever with 208 CVEs including an actively exploited Defender privilege escalation flaw and critical remote...

https://krebsonsecurity.comMay 22

Alleged Kimwolf Botmaster Jacob Butler Arrested and Charged

Canadian authorities arrested 23-year-old Jacob Butler, the suspected operator of Kimwolf, a massive IoT DDoS botnet that infected over 1 million devi...

https://thehackernews.comJun 6

Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attack

A self-replicating worm compromised 73 Microsoft GitHub repositories on June 5, planting credential-harvesting payloads that activate when developers ...

https://thehackernews.comJun 10

Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch Now

Google released security updates for 74 Chrome vulnerabilities, including CVE-2026-11645, a high-severity V8 out-of-bounds memory access flaw.

https://www.cnbc.comJun 10

Beijing escalating AI espionage to catch up with the U.S. on tech, cybersecurity firm says - CNBC

U.S. cybersecurity giant CrowdStrike said China-based entities made over half of state-sponsored cyberattacks on tech firms for artificial ...

https://databreaches.netJun 7

Ex-Threat Intel Exec Accuses IBM and AT&T of Hiding Hacks - DataBreaches.Net

IBM and AT&T lacked basic security controls and hid nation-state hacking breaches from the government, a former IBM threat intelligence official ...


Updated daily