This month: 11 KEVs detected

CISA stopped reliably sending KEV alerts.
We didn't.

CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.

CVE-2026-50751
Check Point · Security Gateway
Check Point Security Gateway Improper Authentication Vulnerability
Detected Jun 8 · 3-day patch deadline
CVE-2026-45247
Mirasvit · Mirasvit Full Page Cache Warmer
Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability
Detected Jun 3 · 3-day patch deadline
CVE-2022-0492
Linux · Kernel
Linux Kernel Improper Authentication Vulnerability
Detected Jun 2 · 3-day patch deadline

KEV Intelligence Brief — June 9, 2026

Prepared for: Federal Contractors · DevOps & Platform Engineering · Security Operations Leadership Brief Date: Tuesday, June 9, 2026 | Entries Covered: 8 CVEs added June 3–9, 2026

CISA's latest KEV additions span network edge infrastructure, AI middleware, browser engines, and legacy Windows components — a cross-stack sweep that signals broad, opportunistic exploitation rather than a single coordinated campaign. Several deadlines have already passed or fall within 72 hours. Treat this brief as an immediate action checklist, not a reading assignment.

Deadline Watch: Edge Infrastructure and VPN Under Active Fire

Three entries targeting network perimeter and SD-WAN infrastructure demand the shortest response windows and carry the highest organizational blast radius.

CVE-2026-50751 (Check Point Security Gateway) is the most urgent entry in this batch. CISA's patch deadline was June 11 — two days from now. The vulnerability is an improper authentication flaw in the IKEv1 key exchange implementation, meaning an unauthenticated remote attacker can bypass password-based authentication entirely and establish a valid remote-access VPN tunnel. This is not a privilege escalation — it is a perimeter elimination. Organizations running Check Point Security Gateway for remote access should treat this as a potential active-breach condition. If patching is not achievable before Thursday, isolate the affected gateway, force-terminate active VPN sessions, rotate all associated service credentials, and verify no lateral movement has occurred from existing VPN-connected sessions. IKEv1 deprecation should be accelerated regardless of patch status.

CVE-2026-20245 (Cisco Catalyst SD-WAN Manager) and CVE-2026-7473 (Arista EOS) both carry a June 23 deadline. The Cisco vulnerability requires local authenticated access to exploit — but in SD-WAN environments, "local" is a relative term. A compromised management plane user or misconfigured RBAC policy is all that separates an attacker from root command execution via a crafted file. Audit who holds authenticated access to vManage consoles immediately. For Arista EOS, the tunneled packet decapsulation flaw is subtle but dangerous in multi-tenant or cloud-interconnect environments: an attacker who can craft packets destined for the switch's decapsulation IP can manipulate forwarding behavior in ways that may bypass segmentation controls. Prioritize EOS patching on any switches handling VXLAN or GRE termination in sensitive network zones.

CVE-2026-28318 (SolarWinds Serv-U) carries a June 19 deadline and requires no authentication whatsoever. A single crafted POST request with a Content-Encoding: deflate header crashes the Serv-U service — an unauthenticated denial-of-service against a file transfer platform. Given SolarWinds' historical targeting by sophisticated threat actors, organizations should assume this is reconnaissance infrastructure for follow-on access attempts, not merely a nuisance DoS. If Serv-U is internet-facing, place it behind authenticated reverse proxy controls immediately and restrict direct access to the management interface.

AI Middleware, Browser Engines, and the Expanding Developer Attack Surface

Two entries reflect an increasingly prominent pattern: adversaries targeting the software delivery and AI toolchain layers that sit beneath production applications.

CVE-2026-42271 (BerriAI LiteLLM) is the most consequential entry for teams running AI gateway or LLM proxy infrastructure. The command injection vulnerability can be triggered by any authenticated user, including holders of low-privilege internal-user API keys — a credential tier that many teams distribute broadly for internal testing and development. A compromised developer laptop or a leaked .env file is sufficient to achieve arbitrary command execution on the LiteLLM host. The patch deadline was June 22. Beyond patching, audit every issued API key, revoke any keys not actively in use, and ensure LiteLLM hosts are not running with elevated OS privileges. Container environments should enforce strict resource isolation and deny host-path mounts for LiteLLM services.

CVE-2026-11645 (Google Chromium V8) is an out-of-bounds read/write flaw enabling sandbox-escaping remote code execution via a crafted HTML page, with a June 23 deadline. This affects Chrome, Microsoft Edge, and Opera wherever those browsers have not been updated. For federal contractors with BOD 22-01 obligations, browser patching is often managed through endpoint management platforms — verify that auto-update policies are enforcing, not merely recommending, the latest stable channel. Managed device fleets that have not received a V8 patch in the last week should be flagged in vulnerability scan output immediately.

Two Overdue Entries: Don't Let Passed Deadlines Become Forgotten Debt

CVE-2026-45247 (Mirasvit Full Page Cache Warmer) had a patch deadline of June 6 — three days ago. This deserialization vulnerability targeting the CacheWarmer cookie allows unauthenticated attackers to achieve RCE on Magento/Adobe Commerce environments. If you are running this extension and have not patched, assume the system may be compromised. Conduct a full web shell audit of the affected web root, review server-side logs for anomalous PHP object injection patterns, and invalidate all session tokens.

CVE-2010-0249 (Microsoft Internet Explorer) is a 16-year-old use-after-free vulnerability that CISA added — and simultaneously marked as overdue on June 3. Its presence signals that at least one federal environment is still running IE in a context where this 2010-era exploit is being actively leveraged. The required action is explicit: discontinue use. If IE cannot be immediately removed due to legacy application dependencies, isolate the host from all network access and initiate an emergency application modernization request.

All entries carry BOD 22-01 applicability for federal agencies. Organizations with cloud-hosted instances of any affected products should apply vendor-specific cloud guidance in parallel with on-premises remediation.

Sources: CISA KEV Catalog · Cisco Security Advisory — SD-WAN Manager · Check Point Security Advisory Portal · Arista Security Advisories · Google Chrome Releases Blog · SolarWinds Security Vulnerability Response · CISA Alert AA22-011A — BOD 22-01 Guidance

Free KEV Alerts

  • Real-time notification the moment a KEV drops
  • Vendor and product details
  • BOD 22-01 deadline included

Pro Alerts Coming Soon

  • Real-time notification the moment a KEV drops
  • Filtered to your specific vendor watchlist
  • Urgency scoring (Critical / Urgent / Standard)
  • Direct patch links included

Stay ahead of CISA.

No spam. Unsubscribe anytime. We don't sell your data.


Upcoming Patch Due Dates

via Binding Operational Directive 22-01

(BOD) 22-01 is a directive issued by the Cybersecurity and Infrastructure Security Agency (CISA) in the United States to federal agencies and federal contractors in order to improve their cybersecurity practices. It provides a set of guidelines and requirements that these agencies and contractors must follow to increase their defenses against cyber threats.

Loading...

News Logo

Cyber Security News

You may have missed...


📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://krebsonsecurity.comJun 9

Pro-Iran Hackers Exploit Meta AI to Hijack High-Value Instagram Accounts

Pro-Iran hackers released videos demonstrating how to exploit Meta's AI support chatbot to reset passwords on Instagram accounts without multi-factor ...

https://www.thezdi.comJun 9

Microsoft June 2026 Patch Tuesday: Record 208 CVEs with Multiple Zero-Days

Microsoft released its largest Patch Tuesday ever with 208 CVEs including an actively exploited Defender privilege escalation flaw and critical remote...

https://krebsonsecurity.comMay 22

Alleged Kimwolf Botmaster Jacob Butler Arrested and Charged

Canadian authorities arrested 23-year-old Jacob Butler, the suspected operator of Kimwolf, a massive IoT DDoS botnet that infected over 1 million devi...

https://thehackernews.comJun 6

Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attack

A self-replicating worm compromised 73 Microsoft GitHub repositories on June 5, planting credential-harvesting payloads that activate when developers ...

https://thehackernews.comJun 10

Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch Now

Google released security updates for 74 Chrome vulnerabilities, including CVE-2026-11645, a high-severity V8 out-of-bounds memory access flaw.

https://www.cnbc.comJun 10

Beijing escalating AI espionage to catch up with the U.S. on tech, cybersecurity firm says - CNBC

U.S. cybersecurity giant CrowdStrike said China-based entities made over half of state-sponsored cyberattacks on tech firms for artificial ...

https://databreaches.netJun 7

Ex-Threat Intel Exec Accuses IBM and AT&T of Hiding Hacks - DataBreaches.Net

IBM and AT&T lacked basic security controls and hid nation-state hacking breaches from the government, a former IBM threat intelligence official ...

https://www.yahoo.comJun 7

An 85-Year-Old Was Told Her Amazon Account Was Hacked. Police Say She Lost $154,000

An 85-year-old Pennsylvania woman was told her Amazon account had been hacked. Police say she later reported losing more than $154000 in a ...


Updated daily