CISA stopped reliably sending KEV alerts.
We didn't.
CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.
KEV Intelligence Brief — June 12, 2026
Prepared for: Federal Contractors · DevOps & Platform Engineering · Security Operations Leadership Classification: TLP:CLEAR | Routine Dissemination Authorized
Deadline Watch: Three Patches Already Overdue or Expiring This Weekend
The most urgent cluster in this week's KEV additions demands immediate attention from network security and remote-access teams. Two deadlines have already passed or expire within hours of this writing.
CVE-2026-50751 (Check Point Security Gateway) carried a patch deadline of June 11 — yesterday. This improper authentication vulnerability in IKEv1 key exchange allows an unauthenticated remote attacker to bypass credential validation entirely and establish a full remote access VPN session. The attack surface here is as dangerous as it gets: no credentials required, no foothold needed, and the payoff is authenticated VPN access to your internal network. If you operate Check Point Security Gateway with IKEv1 enabled and have not applied the vendor hotfix, assume exposure is active. Immediately audit VPN logs for anomalous session establishment, rotate all credentials accessible via the VPN tunnel, and consider disabling IKEv1 in favor of IKEv2 as an interim measure where operationally feasible. This entry is overdue — BOD 22-01 obligations are not satisfied by a pending change ticket.
CVE-2026-10520 (Ivanti Sentry) carries a deadline of June 14 — this Sunday — and falls under the newer BOD 26-04 framework, which adds forensic triage requirements alongside standard patching obligations. This OS command injection flaw enables unauthenticated root-level RCE against Ivanti Sentry, the gateway component that proxies ActiveSync and other mobile device traffic. Ivanti's sustained presence in the KEV catalog over the past two years makes this entry particularly credible for active, targeted exploitation. Beyond patching, BOD 26-04 language specifically requires forensic triage artifacts to be collected before remediation where possible — operations teams should coordinate with their CISO and IR function now, not after the weekend. Internet-exposed Sentry instances should be isolated from internal management networks as an emergency control if patching cannot complete before Sunday.
CVE-2026-28318 (SolarWinds Serv-U) has a deadline of June 19, but given SolarWinds' historical targeting by sophisticated threat actors, early action is warranted. This unauthenticated denial-of-service via a crafted Content-Encoding: deflate POST request can crash the Serv-U service without any credentials, making it trivially weaponizable for disruption campaigns or as a precursor to failover exploitation. File transfer infrastructure is a persistent soft target — patch or network-restrict Serv-U access immediately.
Network Infrastructure and SD-WAN: Elevated Risk Across the Perimeter
Three entries this week target the network fabric itself — the routing, switching, and WAN orchestration layer that most organizations monitor less rigorously than endpoint or application stacks.
CVE-2026-20245 (Cisco Catalyst SD-WAN Manager) involves an improper output escaping vulnerability that allows an authenticated local attacker to escalate to root by supplying a crafted file. While the "authenticated, local" qualifier may tempt some teams to deprioritize this, SD-WAN Manager's administrative plane is a crown-jewel target: control-plane access translates directly to traffic manipulation across all connected branch sites. The realistic threat model here is post-initial-access privilege escalation — patch by June 23 and audit administrative account activity on vManage/SD-WAN Manager instances now.
CVE-2026-7473 (Arista EOS) is an incomplete comparison vulnerability in tunnel decapsulation logic, allowing unexpected tunneled packets with a matching destination IP to be decapsulated and forwarded incorrectly. In high-security environments — government, financial services, defense contractors — this kind of packet-handling flaw in core switching infrastructure represents a covert lateral movement or traffic injection risk that perimeter controls will not catch. Arista EOS operators should apply vendor guidance before June 23 and review tunnel interface configurations for unexpected or legacy encapsulation protocols.
Taken together, these two entries reinforce a consistent pattern: network control planes are under active adversary interest, and the assumption that infrastructure devices are harder to target than application servers is no longer operationally sound.
Developer Toolchains and End-User Browsers: The AI Stack Joins a Familiar Problem Set
CVE-2026-42271 (BerriAI LiteLLM) is a notable entry that signals expanding KEV coverage into AI/LLM middleware. This command injection flaw allows any authenticated user — including low-privilege internal-user key holders — to execute arbitrary commands on the host. LiteLLM is widely deployed as a proxy and load balancer across heterogeneous LLM API backends in enterprise AI pipelines. The threat model is insider threat amplification: any developer or service account with an API key becomes a potential RCE vector. Teams running LiteLLM in shared or multi-tenant environments should treat this as a critical isolation problem, not just a patch exercise. Rotate all API keys post-remediation and audit key issuance policies. Deadline is June 22.
CVE-2026-11645 (Google Chromium V8) is a cross-browser out-of-bounds read/write vulnerability exploitable via a crafted HTML page that achieves sandbox escape. This affects Chrome, Edge, Opera, and any Chromium-derived browser — meaning virtually every enterprise desktop. Apply browser updates immediately; browser patch cycles are typically fast, and the June 23 deadline should be achievable well in advance through standard patch management tooling.
Finally, CVE-2010-0249 (Microsoft Internet Explorer) — a 16-year-old use-after-free vulnerability — has been added with a same-day deadline of June 3, already passed. Its inclusion signals active exploitation in legacy environments. If Internet Explorer is present anywhere in your environment, it should not be: remove it, enforce policy blocking IE-based rendering via Group Policy, and treat any system still running IE as potentially compromised pending investigation.
Sources: CISA KEV Catalog · CISA BOD 22-01 · CISA BOD 26-04 · Ivanti Security Advisory – Sentry · Cisco Security Advisory – SD-WAN Manager · Check Point Security Advisory · Arista Security Advisory – EOS · SolarWinds Security Advisory – Serv-U · Google Chrome Releases
Free KEV Alerts
- Real-time notification the moment a KEV drops
- Vendor and product details
- BOD 22-01 deadline included
Pro Alerts Coming Soon
- Real-time notification the moment a KEV drops
- Filtered to your specific vendor watchlist
- Urgency scoring (Critical / Urgent / Standard)
- Direct patch links included
Stay ahead of CISA.
Common Vulnerability and Exposure
CVEs form a database of known security vulnerabilities that are actively tracked and managed by a group of organizations, such as the U.S. National Cyber Security Alliance. CVEs are an important tool for network security management because they not only provide an inventory of existing vulnerabilities, but also provide information about how the vulnerability can be exploited and instructions on how to protect against it.
Search the KEV Catalog by Vendor or Product
Search for CVEs by vendor or product to identify known exploited vulnerabilities in your environment
Upcoming Patch Due Dates
via Binding Operational Directive 22-01
(BOD) 22-01 is a directive issued by the Cybersecurity and Infrastructure Security Agency (CISA) in the United States to federal agencies and federal contractors in order to improve their cybersecurity practices. It provides a set of guidelines and requirements that these agencies and contractors must follow to increase their defenses against cyber threats.
Loading...
Cyber Security News
You may have missed...
*
Inside a cyberattack: How hackers steal data
The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...
The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm
... cybersecurity company said. "Additionally, LARVA-368 relies heavily on ... The individual's identity has since been outed by cybersecurity ...
Pro-Iran Hackers Exploit Meta AI to Hijack High-Value Instagram Accounts
Pro-Iran hackers released videos demonstrating how to exploit Meta's AI support chatbot to reset passwords on Instagram accounts without multi-factor ...
Microsoft June 2026 Patch Tuesday: Record 208 CVEs with Multiple Zero-Days
Microsoft released its largest Patch Tuesday ever with 208 CVEs including an actively exploited Defender privilege escalation flaw and critical remote...
Alleged Kimwolf Botmaster Jacob Butler Arrested and Charged
Canadian authorities arrested 23-year-old Jacob Butler, the suspected operator of Kimwolf, a massive IoT DDoS botnet that infected over 1 million devi...
Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attack
A self-replicating worm compromised 73 Microsoft GitHub repositories on June 5, planting credential-harvesting payloads that activate when developers ...
Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch Now
Google released security updates for 74 Chrome vulnerabilities, including CVE-2026-11645, a high-severity V8 out-of-bounds memory access flaw.
Beijing escalating AI espionage to catch up with the U.S. on tech, cybersecurity firm says - CNBC
U.S. cybersecurity giant CrowdStrike said China-based entities made over half of state-sponsored cyberattacks on tech firms for artificial ...
Ex-Threat Intel Exec Accuses IBM and AT&T of Hiding Hacks - DataBreaches.Net
IBM and AT&T lacked basic security controls and hid nation-state hacking breaches from the government, a former IBM threat intelligence official ...
Updated daily
