This month: 2 KEVs detected

CISA stopped reliably sending KEV alerts.
We didn't.

CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.

CVE-2024-21182
Oracle · WebLogic Server
Oracle WebLogic Server Unspecified Vulnerability
Detected Jun 1 · 3-day patch deadline
CVE-2026-0257
Palo Alto Networks · PAN-OS
Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
Detected May 29 · 3-day patch deadline
CVE-2026-8398
Daemon · Daemon Tools Lite
Daemon Tools Lite Embedded Malicious Code Vulnerability
Detected May 27 · 3-day patch deadline

Developer Toolchain Under Siege: A Supply Chain Triple-Threat

Three of the six most recent additions to CISA's Known Exploited Vulnerabilities catalog share a common and deeply unsettling trait: the attack surface wasn't a misconfigured server or an unpatched library — it was the developer's own trusted toolchain. CVE-2026-48027 (Nx Console), CVE-2026-45321 (TanStack), and CVE-2026-8398 (Daemon Tools Lite) all involve malicious code embedded or published under trusted identities, then distributed through automatic update mechanisms to developers who did nothing wrong. The Nx Console compromise is particularly notable given CISA's simultaneous advisory on the broader "Megalodon" GitHub CI/CD campaign — these aren't isolated incidents, they're coordinated pressure on the same ecosystem layer.

The pattern here is deliberate targeting of developer trust infrastructure. By poisoning npm packages and VS Code extensions — tools that live inside the development environment itself — threat actors gain access not just to production systems, but to the credentials, tokens, and secrets that build those systems. A compromised CI/CD pipeline is a master key. Federal contractors and any organization operating cloud or DevOps environments should treat credential rotation not as a remediation step but as an immediate operational priority, particularly for any pipeline secrets, API keys, or cloud provider credentials that may have touched an affected environment since mid-May.

Deadline Watch: PAN-OS and WebLogic on the Clock

Two KEVs demand immediate attention this cycle, both with deadlines inside 72 hours. CVE-2026-0257 in Palo Alto Networks PAN-OS is an authentication bypass that allows attackers to establish unauthorized VPN connections — no credentials required. Palo Alto firewalls and VPN concentrators are perimeter infrastructure, meaning a successful exploit doesn't just compromise one system, it compromises the boundary between your network and everything outside it. The patch deadline is Monday. Organizations that haven't patched should treat any recent VPN authentication logs as potentially adversarial and investigate accordingly.

CVE-2024-21182 in Oracle WebLogic Server is equally urgent, with a Thursday deadline. The vulnerability allows unauthenticated attackers with network access via T3 or IIOP protocols to compromise the server entirely — no username, no password, just network reachability. WebLogic sits at the core of enterprise application infrastructure for many large organizations, meaning full data exposure is the realistic worst case here. Any environment running WebLogic with external network access should be treated as a priority patch target before Thursday.

The Zombie in the Room: Internet Explorer, 2010

Finally: CVE-2010-0249. Yes, 2010. Internet Explorer's use-after-free vulnerability made the KEV catalog this week as a reminder that "deprecated" and "safe" are not synonyms. If any system in your environment still touches IE — embedded in kiosks, legacy intranet apps, or aging Windows builds — there is no patch coming. The only remediation is elimination. The fact that CISA still finds this worth cataloging in 2026 tells you everything about the persistence of legacy attack surface in enterprise environments.

Sources: CISA KEV Catalog · CISA Advisory: Nx Console / Megalodon · GitHub Security Advisory GHSA-c9j4-9m59-847w · Ox Security: Megalodon · StepSecurity: Nx Console Compromise

Free KEV Alerts

  • Real-time notification the moment a KEV drops
  • Vendor and product details
  • BOD 22-01 deadline included

Pro Alerts Coming Soon

  • Real-time notification the moment a KEV drops
  • Filtered to your specific vendor watchlist
  • Urgency scoring (Critical / Urgent / Standard)
  • Direct patch links included

Stay ahead of CISA.

No spam. Unsubscribe anytime. We don't sell your data.


Upcoming Patch Due Dates

via Binding Operational Directive 22-01

(BOD) 22-01 is a directive issued by the Cybersecurity and Infrastructure Security Agency (CISA) in the United States to federal agencies and federal contractors in order to improve their cybersecurity practices. It provides a set of guidelines and requirements that these agencies and contractors must follow to increase their defenses against cyber threats.

Loading...

News Logo

Cyber Security News

You may have missed...


📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://www.cnn.comJun 1

Hackers breach senior US Space Force official's Instagram account and post Iranian propaganda

Hackers breached a senior US Space Force official's Instagram account and temporarily posted a string of pro-Iran and anti-US propaganda on Sunday ...

https://www.theblock.coJun 1

Unable to recover from roughly $50 million hack, Radiant Capital is winding down

... hack. Radiant Capital said it hasn't been able to recover a meaningful amount of funds since the 2024 exploit or raise fresh capital, so it plans ...

https://www.msn.comJun 2

Meta AI flaw led to Obama-era White House Instagram hack - MSN

AI exploit revealed: Hackers manipulated Meta's AI support chatbot to reset passwords and take over high-profile Instagram accounts, including the ...

https://uk.finance.yahoo.comJun 2

Hackers trick Meta's own AI into revealing passwords of popular Instagram accounts

One video shows a hacker asking Meta AI chatbot to reset a targeted Instagram account's password using a “password reset email” and instructing it to ...

https://therecord.mediaJun 2

NSA selects new leads for key cybersecurity posts - The Record

David Imbordino, an NSA senior executive who most recently led its cybersecurity directorate in an acting capacity, has been named as its new ...

https://www.scworld.comJun 1

Crypto whales and executives face rising physical attacks | brief | SC Media

Cryptocurrency executives and whales are increasingly becoming targets for criminals worldwide, despite enhanced security measures, as reported by ...

https://cryptonews.netJun 2

Fluid Loses $215,000 in Reward System Exploit After Key Compromise - Cryptonews.net

The exploit highlights a persistent vulnerability in DeFi: the security of off-chain operational infrastructure. ... crypto and blockchain from variou...

https://www.binance.comJun 2

Ethereum Initiates Post-Quantum Security Transition Plan - Binance

Ethereum researcher Thomas Coratger announced the launch of Ethereum's post-quantum security transition plan. According to Foresight News, ...


Updated daily