CISA stopped reliably sending KEV alerts.
We didn't.
CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.
KEV Intelligence Brief — June 15, 2026
Prepared for: Federal Contractors · DevOps & Platform Teams · Security Operations Leaders Classification: Unclassified // For Official Distribution
Deadline Watch: Overdue and Imminent — Act Before the Window Closes
Three vulnerabilities in this batch carry patch deadlines that have already passed or expire today, demanding immediate triage regardless of scheduled maintenance windows.
CVE-2026-10520 (Ivanti Sentry) — deadline June 14 — is the most operationally dangerous entry in this cohort. An unauthenticated remote attacker can achieve root-level remote code execution via OS command injection against a publicly exposed Sentry gateway. Ivanti infrastructure has faced sustained nation-state and criminal targeting over the past several years; treat any unpatched Sentry instance as actively compromised until proven otherwise. Isolate affected appliances from the mobile device management backend, rotate all service credentials tied to the Sentry deployment, and conduct forensic triage per CISA's BOD 26-04 requirements before returning the system to production.
CVE-2026-35273 (Oracle PeopleSoft Enterprise PeopleTools) — deadline June 15 (today) — allows a fully unauthenticated attacker to achieve complete system takeover by exploiting a missing authentication control on a critical function. PeopleSoft environments frequently sit at the intersection of HR, finance, and identity data, making a successful takeover a direct path to bulk credential harvesting and regulatory exposure. Organizations that cannot patch today must immediately firewall PeopleSoft web-facing components and restrict administrative interfaces to named source IPs. BOD 26-04 forensic triage requirements apply.
CVE-2026-54420 (LiteSpeed cPanel Plugin) — deadline June 18 — exploits a UNIX symlink following weakness. While symlink attacks can appear low-severity in isolation, in a shared hosting or CloudLinux/CageFS environment they are a proven mechanism for one tenant to traverse filesystem boundaries and access or overwrite another tenant's files. Hosting providers and managed service operators running LiteSpeed with cPanel must treat this as a tenant-isolation breach risk. The abbreviated three-day deadline signals CISA has observed active exploitation in the wild; disable the plugin or restrict FTP/web-shell access paths until the patch is applied.
Cisco SD-WAN and Network Infrastructure: A Compounding Attack Surface
Two separate Cisco Catalyst SD-WAN Manager vulnerabilities — CVE-2026-20262 (path traversal, deadline June 29) and CVE-2026-20245 (improper output encoding, deadline June 23) — landed in KEV days apart, and their combination tells a more serious story than either entry alone.
CVE-2026-20245 requires local, authenticated access to execute arbitrary commands as root via a crafted file. CVE-2026-20262 enables an authenticated remote attacker to create or overwrite arbitrary files on the filesystem. Chain these two: an attacker who gains any authenticated foothold remotely — through phishing, credential stuffing, or a compromised service account — can use the path traversal to plant a crafted file in the right location, then trigger the output encoding flaw to achieve root-level code execution. The result is an authenticated-but-low-barrier path to full SD-WAN controller compromise, impacting the routing policies, VPN configurations, and network segmentation of every branch governed by that Manager instance.
Federal contractors and operators of distributed WAN infrastructure must prioritize CVE-2026-20245 first (earlier deadline), audit SD-WAN Manager authentication logs for anomalous file operations, and enforce MFA on all management-plane access immediately. Treat the SD-WAN Manager as a Tier-1 critical asset if it governs more than five branch sites or touches classified network segments.
Separately, CVE-2026-7473 (Arista EOS) — deadline June 23 — affects network switching infrastructure at the data-plane level. The incomplete tunnel decapsulation comparison causes EOS to forward packets it should discard, potentially enabling traffic injection or bypass of microsegmentation controls. While exploitation prerequisites are more complex, any organization relying on Arista EOS for zero-trust segmentation enforcement should prioritize this patch and review tunnel interface configurations for unexpected decapsulation endpoints.
AI Infrastructure and the Browser Attack Surface: Expanding Threat Frontiers
Two entries this cycle highlight emerging and persistently exploited attack surfaces that extend well beyond traditional enterprise perimeters.
CVE-2026-42271 (BerriAI LiteLLM) — deadline June 22 — is a command injection flaw that any authenticated user, including low-privilege internal API key holders, can exploit to run arbitrary OS commands on the LiteLLM host. LiteLLM is widely deployed as an internal gateway for routing prompts to multiple LLM providers, meaning a compromised LiteLLM host sits in a privileged position with access to API keys for OpenAI, Anthropic, Azure OpenAI, and other backends. Exploitation here isn't just about one server — it's about exfiltrating every AI provider credential in the environment. DevOps and MLOps teams should patch immediately, audit all issued API keys, rotate LLM provider credentials, and review whether LiteLLM is deployed with least-privilege OS user accounts.
CVE-2026-11645 (Google Chromium V8) — deadline June 23 — is an out-of-bounds read/write vulnerability enabling arbitrary code execution inside the browser sandbox via a crafted HTML page. This affects Chrome, Edge, Opera, and any Electron-based applications embedding Chromium. The sandbox escape risk is the critical factor: weaponized drive-by pages or malicious ads targeting employees in phishing campaigns can deliver this payload passively. Push Chrome/Edge updates via enterprise policy management tools immediately, and verify that Electron-based internal tooling is also updated — these applications are frequently overlooked in browser patch cycles.
Remediation Priority Summary
| Priority | CVE | Deadline | Key Risk | |---|---|---|---| | 🔴 Immediate | CVE-2026-10520 | Overdue (6/14) | Unauthenticated root RCE — Ivanti Sentry | | 🔴 Immediate | CVE-2026-35273 | Today (6/15) | Unauthenticated full takeover — PeopleSoft | | 🟠 Urgent | CVE-2026-54420 | 6/18 | Tenant isolation breach — LiteSpeed cPanel | | 🟡 High | CVE-2026-20245 | 6/23 | Authenticated root RCE — Cisco SD-WAN | | 🟡 High | CVE-2026-42271 | 6/22 | Command injection + AI credential exposure — LiteLLM | | 🟡 High | CVE-2026-11645 | 6/23 | Browser sandbox RCE — Chromium V8 | | 🟡 High | CVE-2026-7473 | 6/23 | Network segmentation bypass — Arista EOS | | 🟢 Elevated | CVE-2026-20262 | 6/29 | File overwrite enabling chain attacks — Cisco SD-WAN |
Sources: CISA KEV Catalog · CISA BOD 26-04 · Cisco Security Advisories · Ivanti Security Advisories · Oracle Critical Patch Update · Google Chrome Releases · Arista Security Advisories · BerriAI LiteLLM GitHub Security
Free KEV Alerts
- Real-time notification the moment a KEV drops
- Vendor and product details
- BOD 26-04 remediation deadline included
Pro Alerts Coming Soon
- Real-time notification the moment a KEV drops
- Filtered to your specific vendor watchlist
- Urgency scoring (Critical / Urgent / Standard)
- Direct patch links included
Stay ahead of CISA.
Common Vulnerability and Exposure
CVEs form a database of known security vulnerabilities that are actively tracked and managed by a group of organizations, such as the U.S. National Cyber Security Alliance. CVEs are an important tool for network security management because they not only provide an inventory of existing vulnerabilities, but also provide information about how the vulnerability can be exploited and instructions on how to protect against it.
Search the KEV Catalog by Vendor or Product
Search for CVEs by vendor or product to identify known exploited vulnerabilities in your environment
Upcoming Patch Due Dates
via Binding Operational Directive 26-04
BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.
Loading...
Cyber Security News
You may have missed...
*
Inside a cyberattack: How hackers steal data
The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...
AUR Supply Chain Attack: 400+ Arch Packages Backdoored with Rootkit and Infostealer
An AUR supply chain attack compromised over 400 Arch Linux packages starting June 11, 2026, planting a Rust-based credential stealer and an eBPF rootk...
Palo Alto Networks PAN-OS GlobalProtect Authentication Bypass Under Active Exploitation
Palo Alto Networks warned that CVE-2026-0257, an authentication bypass vulnerability in PAN-OS GlobalProtect portal and gateway, is being actively exp...
ShinyHunters hacked 100+ orgs by exploiting an Oracle PeopleSoft 0-day
ShinyHunters successfully exploited a critical Oracle PeopleSoft zero-day vulnerability to compromise over 100 organizations across 300 vulnerable ins...
Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters
Google's Mandiant team confirmed that ShinyHunters actively exploited the Oracle PeopleSoft zero-day (CVE-2026-35273) between May 27 and June 9, 2026,...
Agentjacking Attack Tricks AI Coding Agents Into Running Malicious Code
A new class of attack called Agentjacking exploits AI coding agents by injecting malicious code through fake error reports in Sentry, allowing arbitra...
Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw
"Only a small portion of the probed devices actually established VPN sessions, resulting in gateway-connected events." Cybersecurity. The company has ...
Chrome V8 JavaScript Engine Zero-Day (CVE-2026-11645) Under Active Wild Exploitation
Google confirmed that CVE-2026-11645, an out-of-bounds memory access vulnerability in Chrome's V8 JavaScript engine, is being actively exploited in th...
ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities
ShinyHunters exploited a critical unpatched flaw in Oracle PeopleSoft to breach over 100 organizations, primarily targeting universities, stealing dat...
Updated daily
