This month: 11 KEVs detected

CISA stopped reliably sending KEV alerts.
We didn't.

CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.

CVE-2026-50751
Check Point · Security Gateway
Check Point Security Gateway Improper Authentication Vulnerability
Detected Jun 8 · 3-day patch deadline
CVE-2026-45247
Mirasvit · Mirasvit Full Page Cache Warmer
Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability
Detected Jun 3 · 3-day patch deadline
CVE-2022-0492
Linux · Kernel
Linux Kernel Improper Authentication Vulnerability
Detected Jun 2 · 3-day patch deadline

KEV Intelligence Brief — June 9, 2026

Prepared for: Federal Contractors · DevOps & Platform Engineering · Security Operations Leadership Brief Date: Tuesday, June 9, 2026 | Entries Covered: 8 CVEs added June 3–9, 2026

CISA's latest KEV additions span network edge infrastructure, AI middleware, browser engines, and legacy Windows components — a cross-stack sweep that signals broad, opportunistic exploitation rather than a single coordinated campaign. Several deadlines have already passed or fall within 72 hours. Treat this brief as an immediate action checklist, not a reading assignment.

Deadline Watch: Edge Infrastructure and VPN Under Active Fire

Three entries targeting network perimeter and SD-WAN infrastructure demand the shortest response windows and carry the highest organizational blast radius.

CVE-2026-50751 (Check Point Security Gateway) is the most urgent entry in this batch. CISA's patch deadline was June 11 — two days from now. The vulnerability is an improper authentication flaw in the IKEv1 key exchange implementation, meaning an unauthenticated remote attacker can bypass password-based authentication entirely and establish a valid remote-access VPN tunnel. This is not a privilege escalation — it is a perimeter elimination. Organizations running Check Point Security Gateway for remote access should treat this as a potential active-breach condition. If patching is not achievable before Thursday, isolate the affected gateway, force-terminate active VPN sessions, rotate all associated service credentials, and verify no lateral movement has occurred from existing VPN-connected sessions. IKEv1 deprecation should be accelerated regardless of patch status.

CVE-2026-20245 (Cisco Catalyst SD-WAN Manager) and CVE-2026-7473 (Arista EOS) both carry a June 23 deadline. The Cisco vulnerability requires local authenticated access to exploit — but in SD-WAN environments, "local" is a relative term. A compromised management plane user or misconfigured RBAC policy is all that separates an attacker from root command execution via a crafted file. Audit who holds authenticated access to vManage consoles immediately. For Arista EOS, the tunneled packet decapsulation flaw is subtle but dangerous in multi-tenant or cloud-interconnect environments: an attacker who can craft packets destined for the switch's decapsulation IP can manipulate forwarding behavior in ways that may bypass segmentation controls. Prioritize EOS patching on any switches handling VXLAN or GRE termination in sensitive network zones.

CVE-2026-28318 (SolarWinds Serv-U) carries a June 19 deadline and requires no authentication whatsoever. A single crafted POST request with a Content-Encoding: deflate header crashes the Serv-U service — an unauthenticated denial-of-service against a file transfer platform. Given SolarWinds' historical targeting by sophisticated threat actors, organizations should assume this is reconnaissance infrastructure for follow-on access attempts, not merely a nuisance DoS. If Serv-U is internet-facing, place it behind authenticated reverse proxy controls immediately and restrict direct access to the management interface.

AI Middleware, Browser Engines, and the Expanding Developer Attack Surface

Two entries reflect an increasingly prominent pattern: adversaries targeting the software delivery and AI toolchain layers that sit beneath production applications.

CVE-2026-42271 (BerriAI LiteLLM) is the most consequential entry for teams running AI gateway or LLM proxy infrastructure. The command injection vulnerability can be triggered by any authenticated user, including holders of low-privilege internal-user API keys — a credential tier that many teams distribute broadly for internal testing and development. A compromised developer laptop or a leaked .env file is sufficient to achieve arbitrary command execution on the LiteLLM host. The patch deadline was June 22. Beyond patching, audit every issued API key, revoke any keys not actively in use, and ensure LiteLLM hosts are not running with elevated OS privileges. Container environments should enforce strict resource isolation and deny host-path mounts for LiteLLM services.

CVE-2026-11645 (Google Chromium V8) is an out-of-bounds read/write flaw enabling sandbox-escaping remote code execution via a crafted HTML page, with a June 23 deadline. This affects Chrome, Microsoft Edge, and Opera wherever those browsers have not been updated. For federal contractors with BOD 22-01 obligations, browser patching is often managed through endpoint management platforms — verify that auto-update policies are enforcing, not merely recommending, the latest stable channel. Managed device fleets that have not received a V8 patch in the last week should be flagged in vulnerability scan output immediately.

Two Overdue Entries: Don't Let Passed Deadlines Become Forgotten Debt

CVE-2026-45247 (Mirasvit Full Page Cache Warmer) had a patch deadline of June 6 — three days ago. This deserialization vulnerability targeting the CacheWarmer cookie allows unauthenticated attackers to achieve RCE on Magento/Adobe Commerce environments. If you are running this extension and have not patched, assume the system may be compromised. Conduct a full web shell audit of the affected web root, review server-side logs for anomalous PHP object injection patterns, and invalidate all session tokens.

CVE-2010-0249 (Microsoft Internet Explorer) is a 16-year-old use-after-free vulnerability that CISA added — and simultaneously marked as overdue on June 3. Its presence signals that at least one federal environment is still running IE in a context where this 2010-era exploit is being actively leveraged. The required action is explicit: discontinue use. If IE cannot be immediately removed due to legacy application dependencies, isolate the host from all network access and initiate an emergency application modernization request.

All entries carry BOD 22-01 applicability for federal agencies. Organizations with cloud-hosted instances of any affected products should apply vendor-specific cloud guidance in parallel with on-premises remediation.

Sources: CISA KEV Catalog · Cisco Security Advisory — SD-WAN Manager · Check Point Security Advisory Portal · Arista Security Advisories · Google Chrome Releases Blog · SolarWinds Security Vulnerability Response · CISA Alert AA22-011A — BOD 22-01 Guidance

Free KEV Alerts

  • Real-time notification the moment a KEV drops
  • Vendor and product details
  • BOD 22-01 deadline included

Pro Alerts Coming Soon

  • Real-time notification the moment a KEV drops
  • Filtered to your specific vendor watchlist
  • Urgency scoring (Critical / Urgent / Standard)
  • Direct patch links included

Stay ahead of CISA.

No spam. Unsubscribe anytime. We don't sell your data.


Upcoming Patch Due Dates

via Binding Operational Directive 22-01

(BOD) 22-01 is a directive issued by the Cybersecurity and Infrastructure Security Agency (CISA) in the United States to federal agencies and federal contractors in order to improve their cybersecurity practices. It provides a set of guidelines and requirements that these agencies and contractors must follow to increase their defenses against cyber threats.

Loading...

News Logo

Cyber Security News

You may have missed...


📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://databreaches.netJun 7

Ex-Threat Intel Exec Accuses IBM and AT&T of Hiding Hacks - DataBreaches.Net

IBM and AT&T lacked basic security controls and hid nation-state hacking breaches from the government, a former IBM threat intelligence official ...

https://www.yahoo.comJun 7

An 85-Year-Old Was Told Her Amazon Account Was Hacked. Police Say She Lost $154,000

An 85-year-old Pennsylvania woman was told her Amazon account had been hacked. Police say she later reported losing more than $154000 in a ...

https://www.cbc.caJun 8

How scammers manipulate our emotions — and what you can do to protect yourself - CBC

Edmonton police working with ethical hackers, U.S. law enforcement to tackle fraud ... A TD Bank customer says he lost $15K to account hacking. The ba...

https://thehackernews.comJun 8

UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign

Cybersecurity researchers have disclosed details of a financially motivated data theft extortion campaign that has targeted dozens of ...

https://www.cbc.caJun 8

TD Bank holds customer responsible for $15K loss, won't say how account hacking ruled out

A cybersecurity expert says banks are increasingly blaming customers for fraud. When he appealed, the bank said the transactions were conducted using ...

https://www.theverge.comJun 7

Benn Jordan longs for the days of tech that didn't spy on you | The Verge

In short, Benn Jordan has gone from being one of the best music gear YouTubers to one of the best cybersecurity YouTubers. He was kind enough to ...

https://www.cybersecuritydive.comJun 5

Cisco Warns Zero-Day Flaw in SD-WAN is Being Exploited

Cisco warns a zero-day flaw in SD-WAN is being exploited with no current patches available, allowing attackers to conduct command injection attacks.

https://www.bleepingcomputer.comJun 6

Chinese APT deploys new malware to keep access to hacked networks

CISA warned about Brickstorm being deployed by Chinese hackers against VMware vSphere servers, and, more recently, Google reported that it was ...


Updated daily